Описание
When doing a second SMB request to the same host again, curl would wrongly use
a data pointer pointing into already freed memory.
A flaw was found in curl. When handling a second Server Message Block (SMB) request to the same host, curl incorrectly accesses memory that has already been freed. This memory corruption vulnerability, known as a use-after-free, could allow a remote attacker to potentially execute arbitrary code or cause a denial of service.
Отчет
This Moderate flaw in curl's handling of Server Message Block (SMB) connections can lead to a use-after-free vulnerability. When a second SMB request is made to the same host, curl may incorrectly access previously freed memory, potentially resulting in arbitrary code execution or a denial of service. However, successful exploitation is considered difficult due to the specific conditions required to trigger the flaw reliably.
Меры по смягчению последствий
To mitigate this issue, avoid using curl for Server Message Block (SMB) transfers. This can be achieved by ensuring that applications utilizing curl do not initiate SMB requests. If SMB transfers are essential, consider isolating the affected systems or restricting network access to SMB services. A service restart or reload may be required for changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Compute Attestation | build-of-trustee/trustee-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | confidential-compute-attestation-tech-preview/trustee-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-operator-bundle | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-builder-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-rhel9-operator | Fix deferred | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-operator-bundle | Fix deferred | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-rhel9-operator | Fix deferred | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/eventrouter-rhel9 | Fix deferred | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/fluentd-rhel9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.3 Medium
CVSS3
Связанные уязвимости
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
When doing a second SMB request to the same host again, curl would wro ...
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
EPSS
6.3 Medium
CVSS3