The curl SOCKS5 heap overflow: announced as the worst curl flaw in years, and narrower than it sounded
A heap buffer overflow in curl's SOCKS5 proxy handshake. The pre-announcement caused a great deal of alarm, and the conditions it needs turned out to be specific enough that most installations were never exposed.
A fixed package version is available on 6 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.
What it actually is
When curl is told to let the SOCKS5 proxy resolve the host name, and the name is longer than 255 characters, a slow handshake makes curl fall back to resolving locally and copy the oversized name into a buffer sized for the protocol limit.
What an attacker gets: A heap overflow in the process using libcurl, with the content controlled by whoever supplies the host name.
When it applies to you, and when it does not
An old package version and a real exposure are different things. These are the conditions this one needs.
- A SOCKS5 proxy must be configured, with hostname resolution delegated to it. No proxy means no exposure, and that covers the large majority of servers.
- The host name has to exceed 255 characters, so it has to come from somewhere an attacker supplies rather than from a configuration file.
- The slow-handshake path has to be taken, which makes exploitation timing-dependent.
- libcurl matters as much as the curl binary. Applications link the library and are affected through it.
Check your own server
curl --version | head -1 && env | grep -iE 'socks|all_proxy|https?_proxy'The version, and whether a proxy is configured in this environment at all. Check the application's own environment too, not just the shell's.
Fixed package version, per distribution
From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | curl | Fixed | 7.81.0-1ubuntu1.14 |
| Ubuntu 24.04 LTS | curl | Fixed | 8.2.1-1ubuntu3.1 |
| Debian 12 (bookworm) | curl | Fixed | 7.88.1-10+deb12u4 |
| Debian 13 (trixie) | curl | Fixed | 8.3.0-3 |
| Rocky Linux 9 | curl | Fixed | 0:7.76.1-23.el9_2.4 |
| AlmaLinux 9 | curl | Fixed | 7.76.1-26.el9_3.2 |
Install the fix with apt update && apt install --only-upgrade curl on Debian and Ubuntu, or dnf update curl on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
What SecAI has recorded about it
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.
Recorded from nvd. Its weakness class is CWE-787, from NVD.
- http://seclists.org/fulldisclosure/2024/Jan/34
- http://seclists.org/fulldisclosure/2024/Jan/37
- http://seclists.org/fulldisclosure/2024/Jan/38
- https://curl.se/docs/CVE-2023-38545.html
- https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868
- https://lists.fedoraproject.org/archives/list/[email protected]/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ/
Read next
Check whether this vulnerability affects your Linux server
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-38545 included. It changes nothing.