curl: use-after-free and double-free in MQTT sending
Published Sep 23, 2021
9.1
CRITICALCVSS 3.1
EPSS 6.68%
Description
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
Affected products
No data.
Configuration 2
- 33
- 35
Configuration 3
- n/a
- n/a
Configuration 4
- ≥ 5.7.0 · ≤ 5.7.35
- ≥ 8.0.0 · ≤ 8.0.26
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
Running on/with
- n/a
Configuration 15
- 11.0
Configuration 16
- ≥ 8.2.0 · < 8.2.12
- ≥ 9.0.0 · < 9.0.6
- 9.1.0
No data.
.NET Core 2.1 on Red Hat Enterprise Linux
rh-dotnet21-curl
Out of support scope
.NET Core 3.1 on Red Hat Enterprise Linux
rh-dotnet31-curl
Not affected
Red Hat Ceph Storage 2
curl
Out of support scope
Red Hat Enterprise Linux 6
curl
Not affected
Red Hat Enterprise Linux 7
curl
Not affected
Red Hat Enterprise Linux 8
curl
Not affected
Red Hat Enterprise Linux 9
curl
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-curl
Not affected
Red Hat Software Collections
httpd24-curl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| .NET Core 2.1 on Red Hat Enterprise Linux | rh-dotnet21-curl | Out of support scope | n/a |
| .NET Core 3.1 on Red Hat Enterprise Linux | rh-dotnet31-curl | Not affected | n/a |
| Red Hat Ceph Storage 2 | curl | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 9 | curl | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-curl | Not affected | n/a |
| Red Hat Software Collections | httpd24-curl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The MQTT feature is not enabled by default in any of the curl version that Red Hat ships
References (15)
- http://seclists.org/fulldisclosure/2022/Mar/29 mailing-listMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2021-22945 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2001527 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf PatchThird Party Advisory
- https://curl.se/docs/CVE-2021-22945.html
- https://hackerone.com/reports/1269242 ExploitPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/ vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/ vendor-advisoryMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-22945
- https://security.gentoo.org/glsa/202212-01 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20211029-0003/ Third Party Advisory
- https://support.apple.com/kb/HT213183 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-22945
- https://www.debian.org/security/2022/dsa-5197 vendor-advisoryThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
Change history (0)
No recorded changes yet.