Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18924

Опубликовано: 06 сент. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

A flaw was found in libcurl. When libcurl handles HTTP/2 Server Push streams and the parent handle shares connections, a use-after-free vulnerability can occur during the cleanup process. This could lead to application crashes, resulting in a denial of service.

Отчет

This flaw is rated as Low impact. It affects libcurl when configured to use HTTP/2 Server Push with shared connections, a non-default and less common deployment scenario in Red Hat products. Successful exploitation would lead to a use-after-free condition during resource cleanup, primarily impacting service availability.

Меры по смягчению последствий

Disable HTTP/2 Server Push (CURLMOPT_PUSHFUNCTION) and shared connection handles (CURL_LOCK_DATA_CONNECT) in libcurl clients to eliminate the vulnerable code path. If these features cannot be disabled, enforce host-based firewalls to restrict affected applications' outbound HTTPS traffic solely to trusted endpoints, neutralizing the risk of exploitation by malicious HTTP/2 servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred
Red Hat Enterprise Linux 10curlFix deferred
Red Hat Enterprise Linux 10igvmFix deferred
Red Hat Enterprise Linux 10rustFix deferred
Red Hat Enterprise Linux 10s390utilsFix deferred
Red Hat Enterprise Linux 10snphostFix deferred
Red Hat Enterprise Linux 10trusteeFix deferred
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2529201curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections

EPSS

Процентиль: 58%
0.00897
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
15 дней назад

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

CVSS3: 9.1
nvd
15 дней назад

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

msrc
12 дней назад

HTTP/2 server push UAF

CVSS3: 9.1
debian
15 дней назад

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the p ...

CVSS3: 9.1
github
15 дней назад

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

EPSS

Процентиль: 58%
0.00897
Низкий

3.7 Low

CVSS3