Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10536

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via CURLOPT_STREAM_DEPENDS or CURLOPT_STREAM_DEPENDS_E, subsequently invokes curl_easy_reset(), and finally terminates the handle with curl_easy_cleanup(). During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

A flaw was found in libcurl. This use-after-free vulnerability occurs when an application configures an HTTP/2 stream-dependency tree and then performs a sequence of operations involving curl_easy_reset() and curl_easy_cleanup(). During the final cleanup, libcurl attempts to access memory that has already been released. This can lead to application crashes, resulting in a Denial of Service (DoS).

Отчет

This Moderate impact use-after-free flaw in libcurl can lead to application crashes and Denial of Service. It occurs when an application specifically configures an HTTP/2 stream-dependency tree and then performs a precise sequence of curl_easy_reset() and curl_easy_cleanup() operations, attempting to access already freed memory. This vulnerability requires a specific application programming pattern, limiting its exploitability in typical Red Hat deployments.

Меры по смягчению последствий

To mitigate this issue, avoid configuring HTTP/2 stream dependencies within applications utilizing libcurl. This functionality is considered deprecated and its use is required to trigger the vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Not affected
Red Hat Enterprise Linux 10curlAffected
Red Hat Enterprise Linux 10igvmAffected
Red Hat Enterprise Linux 10rustAffected
Red Hat Enterprise Linux 10s390utilsNot affected
Red Hat Enterprise Linux 10snphostAffected
Red Hat Enterprise Linux 10trusteeAffected
Red Hat Enterprise Linux 10trustee-guest-componentsNot affected
Red Hat Enterprise Linux 6curlNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2496766libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service

EPSS

Процентиль: 41%
0.00507
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 месяца назад

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

CVSS3: 9.8
nvd
около 1 месяца назад

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

CVSS3: 4.7
msrc
27 дней назад

HTTP/2 stream-dependency tree UAF

CVSS3: 9.8
debian
около 1 месяца назад

A use-after-free vulnerability exists in libcurl when an application c ...

CVSS3: 9.8
github
около 1 месяца назад

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

EPSS

Процентиль: 41%
0.00507
Низкий

4.7 Medium

CVSS3