Home

Description

Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that results in incorrect destruction order between io_context and endpoint objects.

PUBLISHED Reserved 2025-11-18 | Published 2025-11-24 | Updated 2025-11-24 | Assigner mitre

References

github.com/redboltz/async_mqtt/issues/436

github.com/redboltz/async_mqtt/pull/437

cve.org (CVE-2025-65503)

nvd.nist.gov (CVE-2025-65503)

Download JSON