Описание
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
A flaw was found in libcurl. When libcurl handles HTTP/2 Server Push streams and the parent handle shares connections, a use-after-free vulnerability can occur during the cleanup process. This could lead to application crashes, resulting in a denial of service.
Отчет
This flaw is rated as Low impact. It affects libcurl when configured to use HTTP/2 Server Push with shared connections, a non-default and less common deployment scenario in Red Hat products. Successful exploitation would lead to a use-after-free condition during resource cleanup, primarily impacting service availability.
Меры по смягчению последствий
Disable HTTP/2 Server Push (CURLMOPT_PUSHFUNCTION) and shared connection handles (CURL_LOCK_DATA_CONNECT) in libcurl clients to eliminate the vulnerable code path. If these features cannot be disabled, enforce host-based firewalls to restrict affected applications' outbound HTTPS traffic solely to trusted endpoints, neutralizing the risk of exploitation by malicious HTTP/2 servers.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Compute Attestation | build-of-trustee/trustee-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | curl | Fix deferred | ||
| Red Hat Enterprise Linux 10 | igvm | Fix deferred | ||
| Red Hat Enterprise Linux 10 | rust | Fix deferred | ||
| Red Hat Enterprise Linux 10 | s390utils | Fix deferred | ||
| Red Hat Enterprise Linux 10 | snphost | Fix deferred | ||
| Red Hat Enterprise Linux 10 | trustee | Fix deferred | ||
| Red Hat Enterprise Linux 6 | curl | Not affected | ||
| Red Hat Enterprise Linux 7 | curl | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the p ...
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
EPSS
3.7 Low
CVSS3