Skip to content

Device crash via malformed MQTT packet when downlink is enabled

High
garthvh published GHSA-3x3r-vw9f-pxq5 Aug 27, 2024

Package

No package listed

Affected versions

<= 2.4.0

Patched versions

2.4.1+

Description

Summary

We are disclosing CVE-2024-45038, a denial of serivce vulnerability in MQTT handling, fixed in version 2.4.1 of the Meshtastic firmware and on the Meshtastic public MQTT Broker. It's strongly suggested that all users of Meshtastic, particularly those that connect to a privately hosted MQTT server, update to this or a more recent stable version right away.

After users have had a chance to update their devices we will make the actual proof of concept available

Severity

High

CVE ID

CVE-2024-45038

Weaknesses

No CWEs

Credits