CVE-2019-11779: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 2.7% chance of exploitation in the next 30 days.

In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.

Affected products

  • Canonical Ubuntu Linux: version 19.04 only
  • Debian Debian Linux: version 8.0 only; version 10.0 only
  • Eclipse Mosquitto: from 1.5, before 1.5.9 (fixed in 1.5.9); from 1.6, before 1.6.6 (fixed in 1.6.6)
  • Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
  • Opensuse Backports Sle: version 15.0 only
  • Opensuse Leap: version 15.1 only

Published 2019-09-19. Last modified 2026-06-17.