A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the error message that might be shown to users or otherwise get leaked and revealed.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Aug 22, 2024 | May 26, 2023 |
| Amazon Linux Ami 2 | — | Upgrade curlUpgrade libcurl-develUpgrade libcurlUpgrade curl-debuginfo | Sep 8, 2023 | May 26, 2023 |
| Amazon_linux_2023 | — | Upgrade libcurl-minimalUpgrade curl-minimal-debuginfoUpgrade libcurl-minimal-debuginfoUpgrade libcurl-debuginfoUpgrade curl-minimalUpgrade libcurlUpgrade curl-debuginfoUpgrade curlUpgrade libcurl-develUpgrade curl-debugsource | Feb 17, 2025 | May 17, 2023 |
| Apple Osx Curl | — | Upgrade macOS to the latest version | Jul 25, 2023 | Jul 24, 2023 |
| Debian | — | Upgrade curl | Jul 30, 2024 | May 26, 2023 |
| Freebsd | — | Upgrade curl | May 20, 2023 | May 19, 2023 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Oct 12, 2023 | May 26, 2023 |
| Suse | — | Upgrade libcurl-develUpgrade libcurl4-32bitUpgrade libcurl-devel-32bitUpgrade curlUpgrade libcurl4 | May 18, 2023 | May 17, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 26, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub