CVE-2023-27537
Summary
| CVE | CVE-2023-27537 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-30 20:15:00 UTC |
| Updated | 2024-03-27 14:46:00 UTC |
| Description | A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183816 Debian Security Update for curl (CVE-2023-27537)
- 283820 Fedora Security Update for curl (FEDORA-2023-2884ba1528)
- 284222 Fedora Security Update for curl (FEDORA-2023-0de03a9232)
- 330140 IBM AIX Multiple Vulnerabilities due to curl (curl_advisory2)
- 355390 Amazon Linux Security Advisory for curl : ALAS2-2023-2070
- 355415 Amazon Linux Security Advisory for curl : ALAS2023-2023-193
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 502707 Alpine Linux Security Update for curl
- 502720 Alpine Linux Security Update for curl
- 503104 Alpine Linux Security Update for curl
- 505862 Alpine Linux Security Update for curl
- 691088 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (0d7d104c-c6fb-11ed-8a4b-080027f5fec9)
- 710772 Gentoo Linux curl Multiple Vulnerabilities (GLSA 202310-12)
- 906862 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (25852-1)
- 907388 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (25858-1)