← Back

CVE-2024-2398

nvd nist
Published: Mar 27, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Exploitability: 3.9 / Impact: 4.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

Affected (17)

Products: Haxx: Curl · Apple: Macos · Fedoraproject: Fedora · +1 more
Show all products
1 product
Curl
1 product
Macos
1 product
Fedora
11 products
Active Iq Unified Manager
Brocade Fabric Operating System
Bootstrap Os
H300s Firmware
H410s Firmware
H500s Firmware
H610c Firmware
H610s Firmware
H615c Firmware
H700s Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.44.0 to 8.7.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Before 12.7.6
From 13.0 to 13.6.8
From 14.0 to 14.6
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 39
Version 40
Configuration D
3 vulnerable
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Hci Compute Node
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H300s
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410s
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H500s
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H610c
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H610s
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H615c
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H700s
All versions

References (26)

Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Mailing ListThird Party Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Mailing ListThird Party Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Mailing ListThird Party Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Mailing ListThird Party Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Vendor Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Vendor Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
ExploitIssue TrackingThird Party Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Third Party Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Release NotesVendor Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Release NotesVendor Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.