UBUNTU-CVE-2024-36856

Source
https://ubuntu.com/security/CVE-2024-36856
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-36856.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-36856
Upstream
Published
2024-06-12T03:15:00Z
Modified
2026-09-16T14:01:08Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the daemon by establishing and maintaining a vast number of long-lived malicious publish/subscribe sessions.

References

Affected packages

Ubuntu:22.04:LTS / broker

Package

Name
broker
Purl
pkg:deb/ubuntu/broker?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4.0+ds1-1
1.4.0+ds1-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libbroker2",
            "binary_version": "1.4.0+ds1-1build1"
        },
        {
            "binary_name": "python3-broker",
            "binary_version": "1.4.0+ds1-1build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-36856.json"