Back

CRITICAL

curl: heap based buffer overflow in the SOCKS5 proxy handshake

Published Oct 18, 2023

Description

This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.

When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes.

If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there.

The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.

Affected products

Remediation

Red Hat statement

This flaw does not affect the versions of curl as shipped with Red Hat Enterprise Linux 6, 7, and 8. An overflow is only possible in applications that do not set `CURLOPT_BUFFERSIZE`, or set it smaller than approximately 65kB. Since the curl tool sets `CURLOPT_BUFFERSIZE` to 100kB by default, it is not vulnerable unless rate limiting was set by the user to a size smaller than 65kB. Knowledgebase article: https://access.redhat.com/solutions/7045099

Red Hat mitigation

To avoid this issue, we recommend you do not use `CURLPROXY_SOCKS5_HOSTNAME` proxies with curl. Also do not set a proxy environment variable to socks5h://

Metrics

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Oct 18, 2023
Updated Jul 14, 2026
Reserved Jul 20, 2023
CISA Vulnrichment
Updated Oct 17, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 11, 2023