curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory, libcurl might even call a function pointer in the object, making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct place in memory.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Aug 22, 2024 | Jun 11, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 11, 2021 |
| Freebsd | — | Upgrade mysql57-serverUpgrade mariadb104-serverUpgrade mysql80-serverUpgrade mariadb103-serverUpgrade mariadb105-server | Nov 4, 2022 | Jul 20, 2021 |
| Gentoo Linux | — | Upgrade net-misc/curl. | May 28, 2021 | May 26, 2021 |
| Oracle Mysql | — | Upgrade to MySQL version 5.7.35Upgrade to MySQL version 8.0.26 | Jun 15, 2026 | Jun 11, 2021 |
| Oracle Solaris | — | Upgrade database/mysql-57/client to version 5.7.35-11.4.38.0.1.101.1 on Solaris 11.4Upgrade database/mysql-57/tests to version 5.7.35-11.4.38.0.1.101.1 on Solaris 11.4Upgrade database/mysql-57 to version 5.7.35-11.4.38.0.1.101.1 on Solaris 11.4Upgrade web/curl to version 7.79.0-11.4.39.0.1.107.0 on Solaris 11.4Upgrade database/mysql-57/library to version 5.7.35-11.4.38.0.1.101.1 on Solaris 11.4Upgrade database/mysql-57/embedded to version 5.7.35-11.4.38.0.1.101.1 on Solaris 11.4 | Nov 17, 2021 | Jun 11, 2021 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.0.5Upgrade Splunk Enterprise to version 9.1.1Upgrade Splunk Universal Forwarder to version 9.0.5Upgrade Splunk Enterprise to version 9.0.6Upgrade Splunk Enterprise to version 8.2.12Upgrade Splunk Enterprise to version 8.2.11Upgrade Splunk Universal Forwarder to version 8.1.14Upgrade Splunk Universal Forwarder to version 8.2.11Upgrade Splunk Universal Forwarder to version 9.1.1Upgrade Splunk Universal Forwarder to version 8.2.12Upgrade Splunk Enterprise to version 8.1.14Upgrade Splunk Universal Forwarder to version 9.0.6 | Sep 30, 2025 | Jun 11, 2021 |
| Suse | — | Upgrade libcurl4-32bitUpgrade libcurl-develUpgrade curlUpgrade libcurl4 | Oct 26, 2022 | Jun 11, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 11, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub