|
|
Message-ID: <bcbd7140-4104-e130-0c86-ce5df8acb131@apache.org> Date: Thu, 09 Apr 2026 12:44:03 +0000 From: "Christopher L. Shannon" <cshannon@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2026-40046: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated Severity: moderate Affected versions: - Apache ActiveMQ (org.apache.activemq:apache-activemq) 6.0.0 before 6.2.4 - Apache ActiveMQ All (org.apache.activemq:activemq-all) 6.0.0 before 6.2.4 - Apache ActiveMQ MQTT (org.apache.activemq:activemq-mqtt) 6.0.0 before 6.2.4 Description: Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versions. This issue affects Apache ActiveMQ: from 6.0.0 before 6.2.4; Apache ActiveMQ All: from 6.0.0 before 6.2.4; Apache ActiveMQ MQTT: from 6.0.0 before 6.2.4. Users are recommended to upgrade to version 6.2.4 or a 5.19.x version starting with 5.19.2 or later (currently latest is 5.19.5), which fixes the issue. Credit: Adrien Bernard (finder) References: https://www.cve.org/CVERecord?id=CVE-2025-66168 https://activemq.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-40046
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.