← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-22901

curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory, libcurl might even call a function pointer in the object, making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct place in memory.

No Active Exploit Signals
CVSS Base Score
8.1
HIGH
EPSS Probability:60.12%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-416 ↗Use After Free (CWE-416)

Affected Products & Versions

Vendor Product Affected Versions
haxx curl all
oracle communications_cloud_native_core_binding_support_function 1.11.0
oracle communications_cloud_native_core_network_function_cloud_native_environment 1.10.0
oracle communications_cloud_native_core_network_repository_function 1.15.0, 1.15.1
oracle communications_cloud_native_core_network_slice_selection_function 1.8.0
oracle communications_cloud_native_core_service_communication_proxy 1.15.0
oracle essbase all
oracle mysql_server all
netapp active_iq_unified_manager all
netapp cloud_backup all
netapp oncommand_insight all
netapp oncommand_workflow_automation all
netapp snapcenter all
netapp solidfire\,_enterprise_sds_\&_hci_storage_node all
netapp solidfire_\&_hci_management_node all
netapp solidfire_baseboard_management_controller_firmware all
netapp hci_compute_node_firmware all
netapp hci_compute_node all
netapp h300e_firmware all
netapp h300e all
netapp h300s_firmware all
netapp h300s all
netapp h410s_firmware all
netapp h410s all
netapp h500e_firmware all
netapp h500e all
netapp h500s_firmware all
netapp h500s all
netapp h700e_firmware all
netapp h700e all
netapp h700s_firmware all
netapp h700s all
siemens sinec_infrastructure_network_services all
splunk universal_forwarder 9.1.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
60.122%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHackerOne · Bug Bounty Provider · USA
Reserved2021-01-06T00:00:00
Published2021-06-11T15:49:38
Last Updated2024-08-03T18:58:25

LINK COPIED TO CLIPBOARD