PT-2026-51739 · Libcurl+3 · Libcurl+3
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libcurl (affected versions not specified)
Description
A use-after-free issue exists in libcurl involving the HTTP/2 stream-dependency tree management. This occurs when an application configures the tree using
CURLOPT STREAM DEPENDS or CURLOPT STREAM DEPENDS E, calls the curl easy reset() function, and then terminates the handle via the curl easy cleanup() function. During the final cleanup, the library attempts to access and modify an internal structure that was already freed during the reset operation. This flaw may allow a remote attacker to cause a denial of service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Aix
Linuxmint
Ubuntu
Libcurl