Back

CRITICAL

curl: use-after-free and double-free in MQTT sending

Published Sep 23, 2021

Description

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

Affected products

Remediation

Red Hat statement

The MQTT feature is not enabled by default in any of the curl version that Red Hat ships

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Sep 23, 2021
Updated Jun 9, 2025
Reserved Jan 6, 2021
CISA Vulnrichment
Updated Mar 28, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 15, 2021