https://seclists.org/oss-sec/2024/q1/255: [SECURITY ADVISORY] curl: CVE-2024-2398: HTTP/2 push headers memory-leak
Published Mar 27, 2024
·Updated
Affected Software
1 affected component
curl curl
Frequently Asked Questions
1
What is the severity of CVE-2024-2398?
CVE-2024-2398 is classified as a medium severity vulnerability that causes a memory leak in curl's HTTP/2 push headers handling.
2
How do I fix CVE-2024-2398?
To fix CVE-2024-2398, users should update to the latest version of curl that includes the patch for this vulnerability.
3
What impact does CVE-2024-2398 have on curl users?
CVE-2024-2398 can lead to increased memory consumption and potential denial of service due to the memory leak during HTTP/2 push operations.
4
Which versions of curl are affected by CVE-2024-2398?
CVE-2024-2398 affects all versions of curl before the fix that was implemented in the latest releases following the security advisory.
5
Is CVE-2024-2398 being actively exploited?
As of now, there are no public reports indicating that CVE-2024-2398 is being actively exploited in the wild.