天下漏洞,尽知其名
MEDIUM

CVE-2026-101003 Cesanta Mongoose 栈缓冲区溢出漏洞

影响远程攻击者可触发栈缓冲区溢出,可能导致服务崩溃或执行代码

AI 研判

Cesanta Mongoose 7.21 及更早版本的 MQTT Broker 示例组件存在栈缓冲区溢出漏洞。该漏洞位于 tutorials/mqtt/mqtt-server/main.c 中的 fn 函数,攻击者可远程利用。目前漏洞利用代码已公开,升级到 7.22 版本可修复。

影响范围

Cesanta Mongoose

Cesanta Mongoose 7.21 及更早版本,涉及 MQTT Broker 示例组件(tutorials/mqtt/mqtt-server/main.c)。

漏洞详情

该漏洞属于栈缓冲区溢出(CWE-121),成因是 MQTT Broker 示例代码在处理输入时未正确校验数据长度,导致向栈上固定大小缓冲区写入超长数据。攻击者可远程发送特制 MQTT 报文触发溢出,可能造成服务崩溃,在特定条件下甚至可执行任意代码。

利用条件与风险

攻击者可远程发起利用,无需认证或仅需较低权限;由于利用代码已公开,实战风险较高,可能导致服务拒绝或代码执行。

修复建议

官方已在 7.22 版本中修复(补丁提交 a9df523f76f43a38bd53b4232b9cfd4c16869e71),建议升级至 7.22 或更高版本。临时缓解措施包括限制 MQTT 服务网络暴露、对输入进行严格长度校验,暂无其他公开缓解方案。

原始情报

A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.22 addresses this issue. This patch is called a9df523f76f43a38bd53b4232b9cfd4c16869e71. Upgrading the affected component is advised.