← All CVEs

CVE-2021-22901

high · 8.1

curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory, libcurl might even call a function pointer in the object, making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct place in memory.

8.1
CVSS
60.1%
EPSS (exploit prob.)
99th
EPSS percentile
2021-06-11
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
haxxcurl>= 7.75.0, <= 7.76.1
oraclecommunications_cloud_native_core_binding_support_function1.11.0
oraclecommunications_cloud_native_core_network_function_cloud_native_environment1.10.0
oraclecommunications_cloud_native_core_network_repository_function1.15.0
oraclecommunications_cloud_native_core_network_repository_function1.15.1
oraclecommunications_cloud_native_core_network_slice_selection_function1.8.0
oraclecommunications_cloud_native_core_service_communication_proxy1.15.0
oracleessbase< 11.1.2.4.047
oracleessbase>= 21.0, < 21.3
oraclemysql_server<= 5.7.34
oraclemysql_server>= 8.0.0, <= 8.0.25
netappactive_iq_unified_managerall versions
netappactive_iq_unified_managerall versions
netappcloud_backupall versions
netapponcommand_insightall versions
netapponcommand_workflow_automationall versions
netappsnapcenterall versions
netappsolidfire,_enterprise_sds_&_hci_storage_nodeall versions
netappsolidfire_&_hci_management_nodeall versions
netappsolidfire_baseboard_management_controller_firmwareall versions
netapphci_compute_node_firmwareall versions
netapphci_compute_nodeall versions
netapph300e_firmwareall versions
netapph300eall versions
netapph300s_firmwareall versions
netapph300sall versions
netapph410s_firmwareall versions
netapph410sall versions
netapph500e_firmwareall versions
netapph500eall versions
netapph500s_firmwareall versions
netapph500sall versions
netapph700e_firmwareall versions
netapph700eall versions
netapph700s_firmwareall versions
netapph700sall versions
siemenssinec_infrastructure_network_services< 1.0.1.1
splunkuniversal_forwarder>= 8.2.0, < 8.2.12
splunkuniversal_forwarder>= 9.0.0, < 9.0.6
splunkuniversal_forwarder9.1.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-22901