High severity8.6NVD Advisory· Published Mar 27, 2024· Updated Jun 17, 2026
CVE-2024-2398
CVE-2024-2398
Description
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
43- osv-coords41 versionspkg:apk/chainguard/curlpkg:apk/chainguard/curl-devpkg:apk/chainguard/curl-docpkg:apk/chainguard/curl-oci-entrypointpkg:apk/chainguard/curl-staticpkg:apk/chainguard/libcurl4pkg:apk/chainguard/libcurl-openssl4pkg:apk/wolfi/curlpkg:apk/wolfi/curl-devpkg:apk/wolfi/curl-docpkg:apk/wolfi/curl-oci-entrypointpkg:apk/wolfi/curl-staticpkg:apk/wolfi/libcurl4pkg:apk/wolfi/libcurl-openssl4pkg:rpm/almalinux/curlpkg:rpm/almalinux/curl-minimalpkg:rpm/almalinux/libcurlpkg:rpm/almalinux/libcurl-develpkg:rpm/almalinux/libcurl-minimalpkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/curl&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/curl&distro=openSUSE%20Leap%20Micro%205.4pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Installer%20Updates%2015%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Installer%20Updates%2015%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/curl&distro=SUSE%20Manager%20Proxy%204.3pkg:rpm/suse/curl&distro=SUSE%20Manager%20Server%204.3
< 8.7.1-r0+ 40 more
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 7.76.1-29.el9_4.1
- (no CPE)range: < 7.76.1-29.el9_4.1
- (no CPE)range: < 7.76.1-29.el9_4.1
- (no CPE)range: < 7.76.1-29.el9_4.1
- (no CPE)range: < 7.76.1-29.el9_4.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.7.1-1.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 7.66.0-150200.4.69.1
- (no CPE)range: < 7.66.0-150200.4.69.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-11.86.2
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-11.86.2
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-11.86.2
- (no CPE)range: < 8.6.0-3.1
- (no CPE)range: < 8.0.1-150400.5.44.1
- (no CPE)range: < 8.0.1-150400.5.44.1
Patches
Vulnerability mechanics
References
13- hackerone.com/reports/2402845nvdExploitIssue TrackingThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/18nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/19nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/20nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2024/03/27/3nvdMailing ListThird Party Advisory
- curl.se/docs/CVE-2024-2398.htmlnvdVendor Advisory
- curl.se/docs/CVE-2024-2398.jsonnvdVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20240503-0009/nvdThird Party Advisory
- support.apple.com/kb/HT214118nvdRelease NotesVendor Advisory
- support.apple.com/kb/HT214119nvdRelease NotesVendor Advisory
- support.apple.com/kb/HT214120nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.