Critical severity9.8NVD Advisory· Published Oct 31, 2018· Updated Jun 17, 2026
CVE-2018-16840
CVE-2018-16840
Description
A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the Curl_close() function, the library code first frees a struct (without nulling the pointer) and might then subsequently erroneously write to a struct field within that already freed struct.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16- osv-coords14 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/curl-openssl1&distro=SUSE%20Linux%20Enterprise%20Server%2011-SECURITY
< 7.79.1-1.1+ 13 more
- (no CPE)range: < 7.79.1-1.1
- (no CPE)range: < 7.37.0-37.31.1
- (no CPE)range: < 7.60.0-4.3.1
- (no CPE)range: < 7.60.0-3.14.3
- (no CPE)range: < 7.37.0-70.38.1
- (no CPE)range: < 7.37.0-37.31.1
- (no CPE)range: < 7.60.0-4.3.1
- (no CPE)range: < 7.37.0-70.38.1
- (no CPE)range: < 7.37.0-37.31.1
- (no CPE)range: < 7.60.0-4.3.1
- (no CPE)range: < 7.37.0-70.38.1
- (no CPE)range: < 7.37.0-37.31.1
- (no CPE)range: < 7.60.0-4.3.1
- (no CPE)range: < 7.37.0-70.38.1
- The Curl Project/curlv5Range: from 7.59.0 to 7.61.1
Patches
Vulnerability mechanics
References
6- curl.haxx.se/docs/CVE-2018-16840.htmlnvdPatchVendor Advisory
- github.com/curl/curl/commit/81d135d67155c5295b1033679c606165d4e28f3fnvdPatchThird Party Advisory
- www.securitytracker.com/id/1042013nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/201903-03nvdThird Party Advisory
- usn.ubuntu.com/3805-1/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.