CVE-2023-27537

Name
CVE-2023-27537
Description
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://hackerone.com/reports/1897203
CONFIRM https://security.netapp.com/advisory/ntap-20230420-0010/
Third Party Advisory https://security.gentoo.org/glsa/202310-12

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:haxx:libcurl:7.88.1:*:*:*:*:*:*:* libcurl == None == 7.88.1
cpe:2.3:a:haxx:libcurl:7.88.0:*:*:*:*:*:*:* libcurl == None == 7.88.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
curl edge-main 8.0.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
curl 3.22-main 8.0.0-r0 None fixed
curl 3.21-main 8.0.0-r0 None fixed
curl 3.20-main 8.0.0-r0 None fixed
curl 3.19-main 8.0.0-r0 None fixed
curl 3.18-main 8.0.0-r0 None fixed
curl 3.17-main 7.88.1-r1 Natanael Copa <ncopa@alpinelinux.org> fixed