curl: heap based buffer overflow in the SOCKS5 proxy handshake
Published Oct 18, 2023
9.8
CRITICALCVSS 3.1
EPSS 78.48%
Description
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.
When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes.
If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there.
The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.
Affected products
-
- Version 8.4.0StatusaffectedConstraints<8.4.0
- Version 7.69.0StatusunaffectedConstraints<7.69.0
- Version
Configuration 2
- 37
Configuration 3
- n/a
- n/a
- n/a
- n/a
Configuration 4
- < 10.0.17763.5122
- < 10.0.19044.3693
- < 10.0.19045.3693
- < 10.0.22000.2600
- < 10.0.22621.2715
- < 10.0.22631.2715
- < 10.0.17763.5122
- < 10.0.20348.2113
No data.
JBoss Core Services for RHEL 8
jbcs-httpd24-curl-0:8.4.0-2.el8jbcs
Fixed · RHSA-2023:7625
JBoss Core Services on RHEL 7
jbcs-httpd24-curl-0:8.4.0-2.el7jbcs
Fixed · RHSA-2023:7625
Red Hat Enterprise Linux 9
curl-0:7.76.1-23.el9_2.4
Fixed · RHSA-2023:5763
Red Hat Enterprise Linux 9
curl-0:7.76.1-23.el9_2.4
Fixed · RHSA-2023:5763
Red Hat Enterprise Linux 9
curl-0:7.76.1-26.el9_3.2
Fixed · RHSA-2023:6745
Red Hat Enterprise Linux 9
curl-0:7.76.1-26.el9_3.2
Fixed · RHSA-2023:6745
Red Hat Enterprise Linux 9.0 Extended Update Support
curl-0:7.76.1-14.el9_0.9
Fixed · RHSA-2023:5700
Red Hat Satellite 6.14 for RHEL 8
puppet-agent-0:7.27.0-1.el8sat
Fixed · RHSA-2024:0797
Red Hat Satellite 6.14 for RHEL 8
puppet-agent-0:7.27.0-1.el8sat
Fixed · RHSA-2024:0797
Satellite Client 6 for RHEL 6
puppet-agent-0:7.27.0-1.el6sat
Fixed · RHSA-2024:2011
Satellite Client 6 for RHEL 7
puppet-agent-0:7.27.0-1.el7sat
Fixed · RHSA-2024:2011
Satellite Client 6 for RHEL 8
puppet-agent-0:7.27.0-1.el8sat
Fixed · RHSA-2024:2011
Satellite Client 6 for RHEL 9
puppet-agent-0:7.27.0-1.el9sat
Fixed · RHSA-2024:2011
Red Hat Enterprise Linux 6
curl
Not affected
Red Hat Enterprise Linux 7
curl
Not affected
Red Hat Enterprise Linux 8
curl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services for RHEL 8 | jbcs-httpd24-curl-0:8.4.0-2.el8jbcs | Fixed | RHSA-2023:7625 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-curl-0:8.4.0-2.el7jbcs | Fixed | RHSA-2023:7625 |
| Red Hat Enterprise Linux 9 | curl-0:7.76.1-23.el9_2.4 | Fixed | RHSA-2023:5763 |
| Red Hat Enterprise Linux 9 | curl-0:7.76.1-23.el9_2.4 | Fixed | RHSA-2023:5763 |
| Red Hat Enterprise Linux 9 | curl-0:7.76.1-26.el9_3.2 | Fixed | RHSA-2023:6745 |
| Red Hat Enterprise Linux 9 | curl-0:7.76.1-26.el9_3.2 | Fixed | RHSA-2023:6745 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | curl-0:7.76.1-14.el9_0.9 | Fixed | RHSA-2023:5700 |
| Red Hat Satellite 6.14 for RHEL 8 | puppet-agent-0:7.27.0-1.el8sat | Fixed | RHSA-2024:0797 |
| Red Hat Satellite 6.14 for RHEL 8 | puppet-agent-0:7.27.0-1.el8sat | Fixed | RHSA-2024:0797 |
| Satellite Client 6 for RHEL 6 | puppet-agent-0:7.27.0-1.el6sat | Fixed | RHSA-2024:2011 |
| Satellite Client 6 for RHEL 7 | puppet-agent-0:7.27.0-1.el7sat | Fixed | RHSA-2024:2011 |
| Satellite Client 6 for RHEL 8 | puppet-agent-0:7.27.0-1.el8sat | Fixed | RHSA-2024:2011 |
| Satellite Client 6 for RHEL 9 | puppet-agent-0:7.27.0-1.el9sat | Fixed | RHSA-2024:2011 |
| Red Hat Enterprise Linux 6 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | curl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw does not affect the versions of curl as shipped with Red Hat Enterprise Linux 6, 7, and 8. An overflow is only possible in applications that do not set `CURLOPT_BUFFERSIZE`, or set it smaller than approximately 65kB. Since the curl tool sets `CURLOPT_BUFFERSIZE` to 100kB by default, it is not vulnerable unless rate limiting was set by the user to a size smaller than 65kB. Knowledgebase article: https://access.redhat.com/solutions/7045099
Red Hat mitigation
To avoid this issue, we recommend you do not use `CURLPROXY_SOCKS5_HOSTNAME` proxies with curl. Also do not set a proxy environment variable to socks5h://
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2 other sources (CISA ADP, Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 17, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (30 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 78.48% (0.78483) | 99.57th | v5 (v2026.06.15) |
| Jun 15, 2026 | 78.48% (0.78483) | 99.53th | v5 (v2026.06.15) |
| Mar 4, 2026 | 26.75% (0.26747) | 96.24th | v4 (v2025.03.14) |
| Mar 1, 2026 | 28.33% (0.28327) | 96.43th | v4 (v2025.03.14) |
| Feb 4, 2026 | 26.25% (0.26250) | 96.17th | v4 (v2025.03.14) |
| Feb 1, 2026 | 27.81% (0.27814) | 96.35th | v4 (v2025.03.14) |
| Jan 4, 2026 | 26.25% (0.26250) | 96.13th | v4 (v2025.03.14) |
| Jan 1, 2026 | 27.81% (0.27814) | 96.32th | v4 (v2025.03.14) |
| Dec 4, 2025 | 26.75% (0.26747) | 96.15th | v4 (v2025.03.14) |
| Dec 1, 2025 | 28.33% (0.28327) | 96.34th | v4 (v2025.03.14) |
| Nov 21, 2025 | 26.75% (0.26747) | 96.14th | v4 (v2025.03.14) |
| Nov 18, 2025 | 89.08% (0.89076) | 99.62th | v4 (v2025.03.14) |
| Nov 5, 2025 | 26.75% (0.26747) | 96.12th | v4 (v2025.03.14) |
| Aug 4, 2025 | 22.67% (0.22672) | 95.63th | v4 (v2025.03.14) |
| Aug 1, 2025 | 24.11% (0.24109) | 95.87th | v4 (v2025.03.14) |
| Jul 4, 2025 | 22.67% (0.22672) | 95.59th | v4 (v2025.03.14) |
| Jul 1, 2025 | 24.11% (0.24109) | 95.82th | v4 (v2025.03.14) |
| May 4, 2025 | 18.01% (0.18014) | 94.78th | v4 (v2025.03.14) |
| May 1, 2025 | 19.25% (0.19246) | 95.03th | v4 (v2025.03.14) |
| Apr 15, 2025 | 18.01% (0.18014) | 94.74th | v4 (v2025.03.14) |
| Mar 28, 2025 | 90.10% (0.90104) | 99.57th | v4 (v2025.03.14) |
| Mar 27, 2025 | 88.69% (0.88691) | 99.48th | v4 (v2025.03.14) |
| Mar 17, 2025 | 90.10% (0.90104) | 99.57th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.54% (0.00542) | 78.09th | v3 (v2023.03.01) |
| Apr 21, 2024 | 0.32% (0.00319) | 70.25th | v3 (v2023.03.01) |
| Jan 31, 2024 | 0.18% (0.00178) | 55.17th | v3 (v2023.03.01) |
| Jan 24, 2024 | 0.15% (0.00154) | 51.70th | v3 (v2023.03.01) |
| Oct 28, 2023 | 0.07% (0.00066) | 27.51th | v3 (v2023.03.01) |
| Oct 26, 2023 | 0.09% (0.00091) | 38.51th | v3 (v2023.03.01) |
| Oct 18, 2023 | 0.04% (0.00043) | 7.25th | v3 (v2023.03.01) |
References (25)
- http://seclists.org/fulldisclosure/2024/Jan/34 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/37 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/38 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-38545 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2241933 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://cert-portal.siemens.com/productcert/html/ssa-093430.html
- https://cert-portal.siemens.com/productcert/html/ssa-507364.html
- https://cert-portal.siemens.com/productcert/html/ssa-832273.html
- https://cert-portal.siemens.com/productcert/html/ssa-943925.html
- https://curl.se/docs/CVE-2023-38545.html PatchThird Party Advisory
- https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868
- https://github.com/UTsweetyfish/CVE-2023-38545 exploit
- https://github.com/bcdannyboy/CVE-2023-38545 exploit
- https://github.com/dbrugman/CVE-2023-38545-POC exploit
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ/ Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-38545
- https://security.netapp.com/advisory/ntap-20231027-0009/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240201-0005/ Third Party Advisory
- https://support.apple.com/kb/HT214036 Third Party Advisory
- https://support.apple.com/kb/HT214057 Third Party Advisory
- https://support.apple.com/kb/HT214058 Third Party Advisory
- https://support.apple.com/kb/HT214063 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-38545
- https://www.secpod.com/blog/high-severity-heap-buffer-overflow-vulnerability/ PatchThird Party Advisory
Change history (0)
No recorded changes yet.