CVE-2024-2398

Analyzed
Published: 27 Mar 2024, 07:55
Last modified:13 Feb 2025, 17:40

Vulnerability Summary

Overall Risk (default)
high
52/100
CVSS Score
8.6 HIGH
v3.1 (cve.org)
EPSS Score
36.08% HIGH
36% probability +34.12%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

27 Mar 2024, 07:55
Published
Vulnerability first disclosed
13 Feb 2025, 17:40
Last Modified
Vulnerability information updated

Description

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

CVSS Metrics

  • v3.1HIGHScore: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

EPSS Trends

Current EPSS score: 36.08% Percentile: 98%

Techniques & Countermeasures

  • CWE-772Missing Release of Resource after Effective Lifetime

    The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Affected Systems

  • applemacos

    < 12.7.6 | ≥ 13.0, < 13.6.8 | ≥ 14.0, < 14.6

  • curlcurl

    8.6.0 | 8.5.0 | 8.4.0 | 8.3.0 | 8.2.1 | 8.2.0 | 8.1.2 | 8.1.1 | 8.1.0 | 8.0.1 | 8.0.0 | 7.88.1 | 7.88.0 | 7.87.0 | 7.86.0 | 7.85.0 | 7.84.0 | 7.83.1 | 7.83.0 | 7.82.0 | 7.81.0 | 7.80.0 | 7.79.1 | 7.79.0 | 7.78.0 | 7.77.0 | 7.76.1 | 7.76.0 | 7.75.0 | 7.74.0 | 7.73.0 | 7.72.0 | 7.71.1 | 7.71.0 | 7.70.0 | 7.69.1 | 7.69.0 | 7.68.0 | 7.67.0 | 7.66.0 | 7.65.3 | 7.65.2 | 7.65.1 | 7.65.0 | 7.64.1 | 7.64.0 | 7.63.0 | 7.62.0 | 7.61.1 | 7.61.0 | 7.60.0 | 7.59.0 | 7.58.0 | 7.57.0 | 7.56.1 | 7.56.0 | 7.55.1 | 7.55.0 | 7.54.1 | 7.54.0 | 7.53.1 | 7.53.0 | 7.52.1 | 7.52.0 | 7.51.0 | 7.50.3 | 7.50.2 | 7.50.1 | 7.50.0 | 7.49.1 | 7.49.0 | 7.48.0 | 7.47.1 | 7.47.0 | 7.46.0 | 7.45.0 | 7.44.0

  • fedoraprojectfedora

    39 | 40

  • haxxcurl

    ≥ 7.44.0, < 8.7.0

  • netappactive_iq_unified_manager

    na

  • netappbootstrap_os

    na

  • netappbrocade_fabric_operating_system

    na

  • netapph300s_firmware

    na

  • netapph410s_firmware

    na

  • netapph500s_firmware

    na

  • netapph610c_firmware

    na

  • netapph610s_firmware

    na

  • netapph615c_firmware

    na

  • netapph700s_firmware

    na

  • netappontap_select_deploy_administration_utility

    na

References (13)