Related Vulnerabilities: CVE-2021-28166  

In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted CONNACK message to the broker, a NULL pointer dereference would occur.

Severity Medium

Remote Yes

Type Denial of service

Description

In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted CONNACK message to the broker, a NULL pointer dereference would occur.

AVG-1793 mosquitto 2.0.8-1 Medium Vulnerable

https://bugs.eclipse.org/bugs/show_bug.cgi?id=572608
https://github.com/eclipse/mosquitto/issues/2163
https://github.com/eclipse/mosquitto/commit/6a4a547892184ac7543cfda3ee2294e26be22484