PT-2023-6817 · Curl+11 · Curl+11

Patrick Monnerat

·

Published

2023-02-15

·

Updated

2026-05-18

·

CVE-2023-23916

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions curl versions prior to 7.88.0
Description A flaw in the "chained" HTTP compression algorithms in curl allows a malicious server to insert a virtually unlimited number of compression steps by using many headers, potentially resulting in a denial of service condition due to excessive memory allocation. This could lead to curl spending enormous amounts of allocated heap memory or returning out of memory errors. The issue is related to the decompression chain, where the number of acceptable "links" was capped on a per-header basis, allowing for unlimited compression steps.
Recommendations For versions prior to 7.88.0, update to version 7.88.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the curl command with multiple compression algorithms to minimize the risk of exploitation. Avoid using the curl command with servers that use multiple headers for compression until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALSA-2023:1140
ALSA-2023:1701
ALT-PU-2023-1252
ALT-PU-2023-1292
ALT-PU-2023-5727
AZL-13651
AZL-13653
AZL-13657
AZL-13658
AZL-34602
AZL-37839
BDU:2023-07689
CESA-2023_1140
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2023-23916
DLA-3341-1
DSA-5365-1
MGASA-2023-0054
OESA-2023-1122
OESA-2023-1123
OESA-2023-1124
OESA-2023-1125
OPENSUSE-SU-2023_0429-1
OPENSUSE-SU-2024:12735-1
RHSA-2023:1140
RHSA-2023:1701
RHSA-2023:1842
RHSA-2023:3354
RHSA-2023:3460
RHSA-2023:4139
RHSA-2023_1140
RHSA-2023_1701
RLSA-2023:1140
SUSE-SU-2023:0425-1
SUSE-SU-2023:0429-1
SUSE-SU-2023:1711-1
SUSE-SU-2023:2226-1
SUSE-SU-2023:2228-1
SUSE-SU-2023_0425-1
SUSE-SU-2023_1711-1
USN-5891-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Curl