curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory, libcurl might even call a function pointer in the object, making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct place in memory.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-curl | Aug 22, 2024 | Jun 11, 2021 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jun 11, 2021 | |
| Freebsd | freebsd-upgrade-package-mysql57-serverfreebsd-upgrade-package-mysql80-serverfreebsd-upgrade-package-mariadb103-serverfreebsd-upgrade-package-mariadb104-serverfreebsd-upgrade-package-mariadb105-server | Nov 4, 2022 | Jul 20, 2021 | |
| Gentoo Linux | gentoo-linux-upgrade-net-misc-curl | May 28, 2021 | May 26, 2021 | |
| Oracle Mysql | mysql-upgrade-5_7_35mysql-upgrade-8_0_26 | Jun 15, 2026 | Jun 11, 2021 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-database-mysql-57-5-7-35-11-4-38-0-1-101-1oracle-solaris-11-4-upgrade-database-mysql-57-client-5-7-35-11-4-38-0-1-101-1oracle-solaris-11-4-upgrade-database-mysql-57-embedded-5-7-35-11-4-38-0-1-101-1oracle-solaris-11-4-upgrade-database-mysql-57-library-5-7-35-11-4-38-0-1-101-1oracle-solaris-11-4-upgrade-database-mysql-57-tests-5-7-35-11-4-38-0-1-101-1oracle-solaris-11-4-upgrade-web-curl-7-79-0-11-4-39-0-1-107-0 | Nov 17, 2021 | Jun 11, 2021 | |
| Splunk | splunk-upgrade-latest | Sep 30, 2025 | Jun 11, 2021 | |
| Suse | — | suse-upgrade-curlsuse-upgrade-libcurl-develsuse-upgrade-libcurl4suse-upgrade-libcurl4-32bit | Oct 26, 2022 | Jun 11, 2021 |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jun 11, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub