Expected behavior violation in cURL - CVE-2022-32221
Published: October 26, 2022
Vulnerability details
The vulnerability allows a remote attacker to force unexpected application behavior.
The vulnerability exists due to a logic error for a reused handle when processing subsequent HTTP PUT and POST requests. The libcurl can erroneously use the read callback (CURLOPT_READFUNCTION) to ask for data to send, even when the CURLOPT_POSTFIELDS option has been set, if the same handle previously was used to issue a PUT request, which used that callback. As a result, such behavior can influence application flow and force unpredictable outcome.
Affected software
Amazon Linux AMI
IBM AIX
PowerSC
Debian Linux
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Fedora
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Solaris
macOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Isolation Segment
Data Lakehouse
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Rational ClearCase
IBM QRadar WinCollect Agent
IBM ILOG CPLEX Optimization Studio (COS)
cflinuxfs3
ObjectScale
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
EMC ECS
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
IBM Engineering Requirements Management DOORS Next
EMC Cloud Tiering Appliance
Dell PowerProtect Cyber Recovery
JBoss Core Services
MySQL Server
IBM InfoSphere Information Server
Splunk Universal Forwarder
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
curl (Ubuntu package)
libcurl3 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
davix
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
mysql-server-5.7 (Ubuntu package)
curl-debugsource
libcurl4-32bit
libcurl4
libcurl4-debuginfo
curl
libcurl4-debuginfo-32bit
curl-debuginfo
libcurl4 (Ubuntu package)
libcurl-devel
libcurl4-32bit-debuginfo
libcurl-devel-32bit
libcurl
curl-help
curl (Debian package)
curl (Red Hat package)
net-misc/curl
jbcs-httpd24-curl (Red Hat package)
mysql-server-8.0 (Ubuntu package)
mysql-common
mysql-config
mysql-devel
mysql-test
mysql-help
mysql-server
mysql-debugsource
mysql-errmsg
mysql-debuginfo
mysql
mysql-libs
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
SINEC NMS
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance
RSA Authentication Manager
How to mitigate CVE-2022-32221
cflinuxfs3 - update to 0.330.0
Data Lakehouse - update to 1.1.0.0
ObjectScale - update to 1.3.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
JBoss Core Services - update to 2.4.51 SP1
MySQL Server - addressed in versions 5.7.41, 8.0.32
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
macOS - addressed in versions 12.6.3 21G419, 13.2 22D49
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
curl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
libcurl3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libcurl3-nss (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
libcurl3-gnutls (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-32.el7jbcs, 0.4.10-32.el8jbcs
davix - addressed in versions 0.8.3-1.el7, 0.8.3-1.el8
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-17.el7jbcs, 1.0.0-17.el8jbcs
SINEC NMS - update to 1.0.3.1
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.17-13.el7jbcs, 1.3.17-13.el8jbcs
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-99.el7jbcs, 1.6.1-99.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-20.el7jbcs, 1.15.19-20.el8jbcs
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.43.0-11.el7jbcs, 1.43.0-11.el8jbcs
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-37.el7jbcs, 2.4.51-37.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-22.el7jbcs, 2.9.3-22.el8jbcs
EMC ECS - update to 3.8.0.2
IBM Cloud Transformation Advisor - update to 3.10.0
EMC ViPR SRM - update to 4.8.0.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.1
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
Watson Studio on Cloud Pak for Data - update to 5.0.3
mysql-server-5.7 (Ubuntu package) - update to 5.7.41-0ubuntu0.18.04.1
App Connect Enterprise Certified Container - update to 7.0.0
Dell EMC VxRail Appliance - update to 7.0.411
curl-debugsource - addressed in versions 7.37.0-37.85.1, 7.60.0-4.43.1, 7.60.0-11.49.1, 7.60.0-150000.38.1, 7.66.0-150200.4.42.1, 7.79.1-150400.5.9.1
libcurl4-32bit - addressed in versions 7.37.0-37.85.1, 7.60.0-4.43.1, 7.60.0-11.49.1, 7.60.0-150000.38.1, 7.66.0-150200.4.42.1, 7.79.1-150400.5.9.1
libcurl4 - addressed in versions 7.37.0-37.85.1, 7.60.0-4.43.1, 7.60.0-11.49.1, 7.60.0-150000.38.1, 7.66.0-150200.4.42.1, 7.79.1-150400.5.9.1
libcurl4-debuginfo - addressed in versions 7.37.0-37.85.1, 7.60.0-4.43.1, 7.60.0-11.49.1, 7.60.0-150000.38.1, 7.66.0-150200.4.42.1, 7.79.1-150400.5.9.1
curl - addressed in versions 7.37.0-37.85.1, 7.60.0-4.43.1, 7.60.0-11.49.1, 7.60.0-150000.38.1, 7.66.0-150200.4.42.1, 7.79.1-150400.5.9.1
libcurl4-debuginfo-32bit - addressed in versions 7.37.0-37.85.1, 7.60.0-4.43.1, 7.60.0-11.49.1
curl-debuginfo - addressed in versions 7.37.0-37.85.1, 7.60.0-4.43.1, 7.60.0-11.49.1, 7.60.0-150000.38.1, 7.66.0-150200.4.42.1, 7.79.1-150400.5.9.1
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
libcurl-devel - addressed in versions 7.60.0-11.49.1, 7.60.0-150000.38.1, 7.66.0-150200.4.42.1, 7.79.1-150400.5.9.1
libcurl4-32bit-debuginfo - addressed in versions 7.60.0-150000.38.1, 7.66.0-150200.4.42.1, 7.79.1-150400.5.9.1
libcurl-devel-32bit - addressed in versions 7.66.0-150200.4.42.1, 7.79.1-150400.5.9.1
curl - addressed in versions 7.71.1-19, 7.79.1-12
libcurl-devel - addressed in versions 7.71.1-19, 7.79.1-12
curl-debuginfo - addressed in versions 7.71.1-19, 7.79.1-12
libcurl - addressed in versions 7.71.1-19, 7.79.1-12
curl-debugsource - addressed in versions 7.71.1-19, 7.79.1-12
curl-help - addressed in versions 7.71.1-19, 7.79.1-12
curl (Debian package) - update to 7.74.0-1.3+deb11u5
curl (Red Hat package) - addressed in versions 7.76.1-14.el9_0.6, 7.76.1-19.el9_1.1
curl - addressed in versions 7.79.1-7.fc35, 7.82.0-9.fc36, 7.85.0-2.fc37
curl - update to 7.86.0
net-misc/curl - update to 7.86.0
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.86.0-2.el7jbcs, 7.86.0-2.el8jbcs
curl - update to 7.87.0-2
mysql-server-8.0 (Ubuntu package) - addressed in versions 8.0.32-0buntu0.20.04.1, 8.0.32-0buntu0.22.04.1, 8.0.32-0buntu0.22.10.1
mysql-common - addressed in versions 8.0.35-1, 8.0.38-1
mysql-config - addressed in versions 8.0.35-1, 8.0.38-1
mysql-devel - addressed in versions 8.0.35-1, 8.0.38-1
mysql-test - addressed in versions 8.0.35-1, 8.0.38-1
mysql-help - addressed in versions 8.0.35-1, 8.0.38-1
mysql-server - addressed in versions 8.0.35-1, 8.0.38-1
mysql-debugsource - addressed in versions 8.0.35-1, 8.0.38-1
mysql-errmsg - addressed in versions 8.0.35-1, 8.0.38-1
mysql-debuginfo - addressed in versions 8.0.35-1, 8.0.38-1
mysql - addressed in versions 8.0.35-1, 8.0.38-1
mysql-libs - addressed in versions 8.0.35-1, 8.0.38-1
RSA Authentication Manager - update to 8.7 Patch 2
IBM Rational ClearCase - addressed in versions 9.0.2.7, 9.1.0.4, 10.0.0.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM QRadar WinCollect Agent - update to 10.1.1
IBM InfoSphere Information Server - update to 11.7.1.4
IBM ILOG CPLEX Optimization Studio (COS) - addressed in versions 12.8, 12.9, 12.10, 20.1, 20.1.0.1, 22.1
EMC Cloud Tiering Appliance - update to 13.1.0.2.29
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- Ubuntu update for curl
- Ubuntu update for curl
- SUSE update for curl
- Slackware Linux update for curl
- Multiple vulnerabilities in cflinuxfs3
- Multiple vulnerabilities in IBM ILOG CPLEX Optimization Studio (COS)
- Red Hat JBoss Core Services update for Apache HTTP Server
- Multiple vulnerabilities in IBM QRadar Wincollect agent
- Gentoo update for curl
- Multiple vulnerabilities in Dell SRM and Dell Storage Monitoring and Reporting
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Ventura
- Red Hat Enterprise Linux 9 update for curl
- Ubuntu update for mysql-5.7
- Debian update for curl
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in IBM PowerSC
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Oracle Solaris
- Expected behavior violation in IBM InfoSphere Information Server
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in Siemens SINEC NMS
- Multiple vulnerabilities in Dell ECS
- VMware Tanzu Isolation Segment update for MySQL
- Expected behavior violation in IBM AIX
- Splunk Universal Forwarder update for third-party packages
- Red Hat Enterprise Linux 9.0 Extended Update Support update for curl
- Multiple vulnerabilities in App Connect Enterprise Certified Containe
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in Oracle Solaris third-party software
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- openEuler 20.03 LTS SP1 update for curl
- openEuler 20.03 LTS SP3 update for curl
- openEuler 22.03 LTS update for curl
- openEuler 22.03 LTS SP1 update for mysql
- openEuler 22.03 LTS SP2 update for mysql
- openEuler 22.03 LTS update for mysql
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Amazon Linux AMI update for curl
- openEuler 20.03 LTS SP4 update for mysql
- Fedora 36 update for curl
- Fedora 35 update for curl
- Fedora 37 update for curl
- Fedora EPEL 8 update for davix
- Fedora EPEL 7 update for davix
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Dell ObjectScale