HTTP/2 push headers memory-leak
Vulnerability Description
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-2398
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- w0x42 on hackerone
- Stefan Eissing
References
- https://curl.se/docs/CVE-2024-2398.json
- https://curl.se/docs/CVE-2024-2398.html
- https://hackerone.com/reports/2402845
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/
- http://www.openwall.com/lists/oss-security/2024/03/27/3
- https://security.netapp.com/advisory/ntap-20240503-0009/
- https://support.apple.com/kb/HT214119
- https://support.apple.com/kb/HT214118
- https://support.apple.com/kb/HT214120
- http://seclists.org/fulldisclosure/2024/Jul/20
- http://seclists.org/fulldisclosure/2024/Jul/18
- http://seclists.org/fulldisclosure/2024/Jul/19
More from curl
View All →Affected Vendor
curl
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.