CVE-2019-11779: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 2.7% chance of exploitation in the next 30 days.
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
Affected products
- Canonical Ubuntu Linux: version 19.04 only
- Debian Debian Linux: version 8.0 only; version 10.0 only
- Eclipse Mosquitto: from 1.5, before 1.5.9 (fixed in 1.5.9); from 1.6, before 1.6.6 (fixed in 1.6.6)
- Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.1 only
Published 2019-09-19. Last modified 2026-06-17.