cbcvebase.
CVE-2023-23916
published 2023-02-23

CVE-2023-23916: An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that…

PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.70%
74.3th percentile
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a "malloc bomb", making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiancurl< curl 7.88.1-1 (bookworm)curl 7.88.1-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
haxxcurl>= 0 < 7.74.0-1.3+deb11u77.74.0-1.3+deb11u7
haxxcurl>= 0 < 7.88.1-17.88.1-1
haxxcurl>= 0 < 7.88.1-17.88.1-1
haxxcurl>= 0 < 7.88.1-17.88.1-1
haxxcurl>= 0 < 7.58.0-2ubuntu3.237.58.0-2ubuntu3.23
haxxcurl>= 0 < 7.68.0-1ubuntu2.167.68.0-1ubuntu2.16
haxxcurl>= 0 < 7.81.0-1ubuntu1.87.81.0-1ubuntu1.8
haxxcurl>= 7.57.0 < 7.88.07.88.0
httpsgithub.com_curl_curl
msrcazl3_cmake_3.21.4-10_on_azure_linux_3.0
msrcazl3_cmake_3.28.2-1_on_azure_linux_3.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_cmake_3.21.4-13_on_cbl_mariner_2.0
msrccbl2_curl_7.88.1-1_on_cbl_mariner_2.0
msrccbl2_mysql_8.0.33-1_on_cbl_mariner_2.0
msrccbl2_rust_1.72.0-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_oracle7.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.