Back

HIGH

HTTP/2 push headers memory-leak

Published Mar 27, 2024

Description

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner curl
Published Mar 27, 2024
Updated Feb 13, 2025
Reserved Mar 12, 2024
CISA Vulnrichment
Updated Apr 26, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 27, 2024