When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-curl | Aug 22, 2024 | Sep 23, 2021 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-curlamazon-linux-ami-2-upgrade-curl-debuginfoamazon-linux-ami-2-upgrade-libcurlamazon-linux-ami-2-upgrade-libcurl-devel | Jul 4, 2022 | Sep 23, 2021 | |
| Apple Osx Curl | apple-osx-upgrade-latest | Mar 18, 2022 | Sep 23, 2021 | |
| Debian | debian-upgrade-curl | Nov 4, 2022 | Sep 23, 2021 | |
| Freebsd | freebsd-upgrade-package-curl | Nov 4, 2022 | Sep 17, 2021 | |
| Gentoo Linux | gentoo-linux-upgrade-net-misc-curl | Dec 19, 2022 | Sep 23, 2021 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-web-curl-7-79-0-11-4-39-0-1-107-0 | Nov 17, 2021 | Sep 23, 2021 | |
| Splunk | splunk-upgrade-latest | Sep 30, 2025 | Sep 23, 2021 | |
| Suse | — | suse-upgrade-curlsuse-upgrade-libcurl-develsuse-upgrade-libcurl4suse-upgrade-libcurl4-32bit | Oct 26, 2022 | Sep 23, 2021 |
| Ubuntu | ubuntu-upgrade-curlubuntu-upgrade-libcurl3-gnutlsubuntu-upgrade-libcurl3-nssubuntu-upgrade-libcurl4 | Sep 16, 2021 | Sep 15, 2021 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Sep 23, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub