CVE-2023-27537
Description
Double free vulnerability in libcurl <8.0.0 when sharing HSTS data across threads due to missing mutexes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Double free vulnerability in libcurl <8.0.0 when sharing HSTS data across threads due to missing mutexes.
Vulnerability
A double-free vulnerability exists in libcurl versions prior to 8.0.0 when sharing HSTS data between separate handles. The sharing was introduced without thread safety considerations, and the documentation did not warn about concurrent use. Missing mutexes or thread locks allow two threads sharing the same HSTS data to trigger a double-free or use-after-free [1].
Exploitation
An attacker must cause two threads to share the same HSTS data and access it concurrently. This could be achieved if the attacker controls the threading behavior of an application using libcurl, or by exploiting another vulnerability that leads to shared HSTS state. No authentication or network position is required; the vulnerability is triggered locally through concurrent thread execution.
Impact
Successful exploitation results in a double-free or use-after-free condition, potentially leading to memory corruption. This could allow an attacker to execute arbitrary code or cause a denial of service. The confidentiality, integrity, and availability of the affected system may be compromised.
Mitigation
Upgrade to libcurl version 8.0.0 or later, which contains the fix. Gentoo users should upgrade to >=net-misc/curl-8.3.0-r2 [1]. No known workaround exists for earlier versions.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- security.gentoo.org/glsa/202310-12mitrevendor-advisory
- hackerone.com/reports/1897203mitre
- security.netapp.com/advisory/ntap-20230420-0010/mitre
News mentions
0No linked articles in our index yet.