CVE-2024-2398: HTTP/2 push headers memory-leak
Accounts. The issue was addressed with improved checks.
Other sources
AirDrop. This issue was addressed through improved state management.
— Apple
apache. This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
APFS. The issue was addressed with improved restriction of data container access.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue was addressed with additional code-signing restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.74.0-1.3+deb11u13Fixed in 7.88.1-10+deb12u7Fixed in 8.10.1-2 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.6 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.7.6 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.6.8 - Upgrade
Upgrade
redhat/curlto a version that resolves this vulnerability.Fixed in 8.7.0 - Upgrade
Upgrade
curl/curl (libcurl)to a version that resolves this vulnerability.Patch CVE-2024-2398 - Configuration
If you do not require HTTP/2 server push, do not allow it in your libcurl configuration to avoid the memory leak/DoS condition described for CVE-2024-2398.
libcurl (HTTP/2 server push) HTTP/2 server push allowance (allow server push) = disable (do not allow HTTP/2 server push) - Compensating control
If you allow HTTP/2 server push, enforce/limit the number of received headers for PUSH_PROMISE to the maximum allowed limit (1000) so libcurl aborts the server push instead of leaking memory.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-40804
- CVE-2023-38709
- CVE-2024-24795
- CVE-2024-27316
- CVE-2024-40783
- CVE-2024-40774
- CVE-2024-40814
- CVE-2024-40775
- CVE-2024-27877
- CVE-2024-27878
- CVE-2024-40799
- CVE-2024-27873
- CVE-2024-2004
- CVE-2024-2379
- CVE-2024-2398
- CVE-2024-2466
- CVE-2024-40827
- CVE-2024-40815
- CVE-2024-40795
- CVE-2023-6277
- CVE-2023-52356
- CVE-2024-40806
- CVE-2024-40777
- CVE-2024-40784
- CVE-2024-27863
- CVE-2024-40816
- CVE-2024-40788
- CVE-2024-40803
- CVE-2024-40805
- CVE-2024-40832
- CVE-2024-40796
- CVE-2024-6387
- CVE-2024-40781
- CVE-2024-40802
- CVE-2024-40823
- CVE-2024-27882
- CVE-2024-27883
- CVE-2024-40778
- CVE-2024-40800
- CVE-2023-27952
- CVE-2024-40817
- CVE-2024-40824
- CVE-2024-27871
- CVE-2024-27881
- CVE-2024-40821
- CVE-2024-40798
- CVE-2024-27872
- CVE-2024-27862
- CVE-2024-40833
- CVE-2024-40835
- CVE-2024-40836
- CVE-2024-40807
- CVE-2024-40834
- CVE-2024-40809
- CVE-2024-40812
- CVE-2024-40787
- CVE-2024-40793
- CVE-2024-40818
- CVE-2024-40822
- CVE-2024-40828
- CVE-2024-40811
- CVE-2024-40776
- CVE-2024-40782
- CVE-2024-40779
- CVE-2024-40780
- CVE-2024-40785
- CVE-2024-40789
- CVE-2024-4558
- CVE-2024-40794
- CVE-2024-27826
- CVE-2024-23296
- CVE-2024-44205
- CVE-2024-23261
- CVE-2024-40786
- CVE-2024-40829
- CVE-2024-54564
- CVE-2024-44306
- CVE-2024-44307
- CVE-2024-44141
- CVE-2024-44199
- CVE-2024-40810
- CVE-2024-44305
- CVE-2024-54551
- CVE-2024-44185
- CVE-2024-44206
Frequently Asked Questions
What is the severity of CVE-2024-2398?
CVE-2024-2398 is classified as a denial of service vulnerability with a medium severity due to its potential for causing system instability.
How do I fix CVE-2024-2398?
To fix CVE-2024-2398, update to the patched versions of cURL as specified by the respective vendors.
What systems are affected by CVE-2024-2398?
CVE-2024-2398 affects multiple versions of cURL on various platforms including macOS Monterey, macOS Ventura, macOS Sonoma, and IBM Cognos Dashboards.
What type of attack does CVE-2024-2398 allow?
CVE-2024-2398 allows a remote attacker to exploit a memory leak vulnerability through specially crafted HTTP/2 PUSH_PROMISE frames.
Can CVE-2024-2398 cause data loss?
While CVE-2024-2398 primarily causes a denial of service condition, it does not directly lead to data loss but may impact availability.