High severity7.5NVD Advisory· Published May 26, 2023· Updated Jun 17, 2026
CVE-2023-28319
CVE-2023-28319
Description
A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the error message that might be shown to users or otherwise get leaked and revealed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- osv-coords10 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/curl&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 8.0.1-150400.5.23.1+ 9 more
- (no CPE)range: < 8.0.1-150400.5.23.1
- (no CPE)range: < 8.0.1-150400.5.23.1
- (no CPE)range: < 8.0.1-150400.5.23.1
- (no CPE)range: < 8.1.0-1.1
- (no CPE)range: < 8.0.1-150400.5.23.1
- (no CPE)range: < 8.0.1-150400.5.23.1
- (no CPE)range: < 8.0.1-150400.5.23.1
- (no CPE)range: < 8.0.1-11.65.2
- (no CPE)range: < 8.0.1-11.65.2
- (no CPE)range: < 8.0.1-11.65.2
Patches
Vulnerability mechanics
References
9- hackerone.com/reports/1913733nvdExploitPatchThird Party Advisory
- seclists.org/fulldisclosure/2023/Jul/47nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2023/Jul/48nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2023/Jul/52nvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202310-12nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20230609-0009/nvdThird Party Advisory
- support.apple.com/kb/HT213843nvdThird Party Advisory
- support.apple.com/kb/HT213844nvdThird Party Advisory
- support.apple.com/kb/HT213845nvdThird Party Advisory
News mentions
0No linked articles in our index yet.