CVE-2024-2398 Details
Description
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 26, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-772 | Missing Release of Resource after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| haxx curl | >= 7.44.0, < 8.7.0 |
CPE
Remediation
| |
| apple macos | < 12.7.6 >= 13.0, < 13.6.8 >= 14.0, < 14.6 |
CPE
Remediation
| |
| fedoraproject fedora | 39 40 |
CPE
Remediation
| |
| netapp active iq unified manager | All versions |
CPE
Remediation
| |
| netapp ontap select deploy administration utility | All versions |
CPE
Remediation
| |
| netapp brocade fabric operating system | All versions |
CPE
Remediation
| |
| netapp bootstrap os | All versions |
CPE
Remediation
| |
| netapp hci compute node | All versions |
CPE
Remediation
| |
| netapp h300s firmware | All versions |
CPE
Remediation
| |
| netapp h300s | All versions |
CPE
Remediation
| |
| netapp h410s firmware | All versions |
CPE
Remediation
| |
| netapp h410s | All versions |
CPE
Remediation
| |
| netapp h500s firmware | All versions |
CPE
Remediation
| |
| netapp h500s | All versions |
CPE
Remediation
| |
| netapp h610c firmware | All versions |
CPE
Remediation
| |
| netapp h610c | All versions |
CPE
Remediation
| |
| netapp h610s firmware | All versions |
CPE
Remediation
| |
| netapp h610s | All versions |
CPE
Remediation
| |
| netapp h615c firmware | All versions |
CPE
Remediation
| |
| netapp h615c | All versions |
CPE
Remediation
| |
| netapp h700s firmware | All versions |
CPE
Remediation
| |
| netapp h700s | All versions |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | curl |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 30, 2024 | CVE Modified | curl |
| Jul 30, 2024 | CVE Modified | curl |
| Jul 29, 2024 | CVE Modified | curl |
| Jul 3, 2024 | CVE Modified | CISA-ADP |
| May 14, 2024 | CVE Modified | curl |
| May 3, 2024 | CVE Modified | curl |
| May 1, 2024 | CVE Modified | curl |
| Apr 25, 2024 | CVE Modified | curl |
| Apr 19, 2024 | CVE Modified | curl |
| Mar 27, 2024 | New CVE Received | curl |