CVE-2017-7652: Debian Linux

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the configuration to be reloaded from disk. If there are lots of clients connected so that there are no more file descriptors/sockets available (default limit typically 1024 file descriptors on Linux), then opening the configuration file will fail.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Eclipse Mosquitto: from 1.0, up to and including 1.4.14

Published 2018-04-25. Last modified 2026-06-17.