CVE-2024-7264

The libcurl ASN.1 time parser read: an out-of-bounds read while parsing a certificate date

libcurl reads past the end of a buffer while parsing a generalized time field in an ASN.1 structure, which in practice means a certificate. A hostile server can trigger it during a TLS handshake.

curlNot in CISA’s Known Exploited catalogueEPSS 17.3% chance of an attempt in 30 daysCVSS 6.5CWE-125CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

A fixed package version is available on 4 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

The GTime2str() function, used when parsing ASN.1 generalized time values, could read beyond the data it was given when handed a malformed value. That value arrives in a certificate, before any of the application's own logic runs.

What an attacker gets: An out-of-bounds read. Information disclosure from adjacent memory, or a crash of the process using libcurl.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • It is reached when curl inspects certificate details, which is not every request but is common in applications that report on certificates.
  • A hostile or compromised server is enough; the attacker does not need to be on the network path.
  • Anything linking libcurl is affected, not only the command-line tool. Restart long-running services after the upgrade.

Check your own server

Read-only, changes nothing
curl --version | head -1

The binary version. The library version is what matters for services, and it is the package version in the table below.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTScurlFixed7.81.0-1ubuntu1.17
Ubuntu 24.04 LTScurlFixed8.5.0-2ubuntu10.2
Debian 12 (bookworm)curlFixed7.88.1-10+deb12u7
Debian 13 (trixie)curlFixed8.9.1-1
Rocky Linux 9curlNo advisory names itno advisory for this release names it
AlmaLinux 9curlNo advisory names itno advisory for this release names it

Install the fix with apt update && apt install --only-upgrade curl on Debian and Ubuntu, or dnf update curl on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

Recorded from nvd. Its weakness class is CWE-125, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2024-7264 included. It changes nothing.