Amazon Linux 2 Security Advisory: ALAS-2023-2271
Advisory Release Date: 2023-09-27 22:48 Pacific
Advisory Updated Date: 2023-10-05 22:03 Pacific
HTTP headers eat all memory
NOTE: https://www.openwall.com/lists/oss-security/2023/09/13/1
NOTE: https://curl.se/docs/CVE-2023-38039.html
NOTE: Introduced by: https://github.com/curl/curl/commit/7c8c723682d524ac9580b9ca3b71419163cb5660 (curl-7_83_0)
NOTE: Experimental tag removed in: https://github.com/curl/curl/commit/4d94fac9f0d1dd02b8308291e4c47651142dc28b (curl-7_84_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/3ee79c1674fd6f99e8efca52cd7510e08b766770 (curl-8_3_0) (CVE-2023-38039)
Affected Packages:
curl
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update curl to update your system.
aarch64:
curl-8.3.0-1.amzn2.0.1.aarch64
libcurl-8.3.0-1.amzn2.0.1.aarch64
libcurl-devel-8.3.0-1.amzn2.0.1.aarch64
curl-debuginfo-8.3.0-1.amzn2.0.1.aarch64
i686:
curl-8.3.0-1.amzn2.0.1.i686
libcurl-8.3.0-1.amzn2.0.1.i686
libcurl-devel-8.3.0-1.amzn2.0.1.i686
curl-debuginfo-8.3.0-1.amzn2.0.1.i686
src:
curl-8.3.0-1.amzn2.0.1.src
x86_64:
curl-8.3.0-1.amzn2.0.1.x86_64
libcurl-8.3.0-1.amzn2.0.1.x86_64
libcurl-devel-8.3.0-1.amzn2.0.1.x86_64
curl-debuginfo-8.3.0-1.amzn2.0.1.x86_64