Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CVE-2023-38545 is a high-severity heap-based buffer overflow in curl’s SOCKS5 proxy handshake. The curl project says upstream libcurl versions 7.69.0 through 8.3.0 are affected and fixed the flaw in curl 8.4.0, released October 11, 2023. Despite the supplied title’s use of “Critical,” the project classifies the vulnerability as High, not Critical. It remains an enterprise concern where affected or unpatched builds are still deployed, including inside applications and containers, particularly when SOCKS5 remote hostname resolution is used.

What CVE-2023-38545 does

The flaw affects the SOCKS5 proxy handshake when curl sends a hostname to the proxy for resolution. SOCKS5 allows a hostname field of up to 255 bytes. When a hostname is longer, curl should resolve it locally and send the resulting address to the proxy instead.

Under a sufficiently slow SOCKS5 handshake, a bug could leave curl using the wrong resolution choice. The longer hostname could then be copied into a target buffer and overflow heap memory. The curl project says the bug originated when the SOCKS5 handshake was converted to a non-blocking state machine. The advisory also describes an additional hostname-length integer-overflow scenario that could allow a handshake to complete even when the buffer size prevents the described heap overflow; that detail is not evidence of widespread exploitation.

The advisory notes that the curl command-line tool uses a 102,400-byte transfer buffer by default, while rate limiting below 65,541 bytes per second makes it use a smaller buffer. Those details describe the command-line tool’s behavior and should not be generalized to every application using libcurl.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is my curl or libcurl version affected?

The upstream affected range is libcurl 7.69.0 through 8.3.0 inclusive. The curl project lists versions below 7.69.0 and versions 8.4.0 or later as not affected by this flaw. The project published its advisory and released 8.4.0 on October 11, 2023; the issue was reported on September 30, 2023. See the curl project’s CVE-2023-38545 advisory.

Version alone does not establish that a system is exploitable. The relevant configuration uses SOCKS5 remote hostname resolution, and the described overflow requires a sufficiently long hostname and a slow enough handshake for the faulty state to occur. Conversely, checking only the system’s curl executable can miss vulnerable libcurl copies bundled with applications or containers. The curl project notes that libcurl is used by applications that do not always advertise it as a dependency.

Rank #2
Sale
Curly Girl: The Handbook
  • Workman publishing
  • Binding: paperback
  • Language: english

Check for the SOCKS5 remote-hostname path

In the curl command-line tool, inspect configurations and scripts for --socks5-hostname, --proxy or --preproxy using a socks5h:// URL, and proxy environment variables set to a socks5h:// URL. The libcurl API has corresponding proxy settings. These are paths to investigate, not proof that every machine with curl installed is vulnerable.

How to check Linux distribution packages

Distribution packages may contain a backported fix while retaining an upstream version string that looks older than 8.4.0. Assess the installed package against the security status and advisory for the exact distribution release, repository, and build; do not rely on an upstream version comparison alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Package source What the available vendor information says What to verify
Upstream curl/libcurl Versions 7.69.0–8.3.0 are affected; 8.4.0 fixed the flaw. Confirm the actual library version and whether the application uses the SOCKS5 remote-hostname path.
Debian The tracker shows fixed statuses for the listed bookworm, trixie, forky, and sid package rows; package version strings need not match the upstream fixed-version number. Check the current tracker entry for the installed release and package build: Debian CVE-2023-38545 tracker.
Red Hat Red Hat lists fixed errata for RHEL 9 and named related products, and says curl versions shipped with RHEL 6, 7, and 8 are not affected. Red Hat backports fixes without necessarily rebasing to a newer upstream version. Check the current status and applicable erratum for the precise product and installed build: Red Hat CVE-2023-38545 page.

Vendor statuses can vary by release, repository, and build, so the examples above are not a substitute for checking the current vendor record for the package actually installed.

What enterprise teams should do

  1. Inventory curl and libcurl. Identify system packages and also libraries bundled in applications, container images, and other deployed software. Include the installed package build and its vendor source in the inventory.
  2. Review proxy configuration. Look for SOCKS5 remote hostname resolution, including the command-line options, URL scheme, environment variables, or corresponding libcurl settings described above.
  3. Remediate using the correct source. For an upstream build, upgrade to curl 8.4.0 or later or apply the project’s patch. If immediate remediation is not possible, discontinue the affected SOCKS5 remote-hostname configuration while arranging an update. For distribution packages, apply the vendor’s fixed package or erratum for the exact release rather than judging by the upstream version string.
  4. Validate the deployed change. Confirm that the package or rebuilt binary is the intended fixed build and that affected applications and containers are updated. Remove temporary configuration mitigations through the organization’s change process when appropriate. The curl advisory and vendor pages do not prescribe one universal enterprise validation test.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Severity and impact context

The curl project rates CVE-2023-38545 High and identifies it as CWE-122, a heap-based buffer overflow. Its advisory lists a $4,660 bounty; that figure is an award, not an estimate of financial impact or loss. The cited project and vendor records do not establish a broader count of affected enterprise installations, confirmed exploitation, or financial impact.

Quick Recap

SaleBestseller No. 2
Curly Girl: The Handbook
Curly Girl: The Handbook
Workman publishing; Binding: paperback; Language: english
$8.19
Bestseller No. 3
Bestseller No. 4
SaleBestseller No. 5
A Practical Guide to Curl (Programming Series)
A Practical Guide to Curl (Programming Series)
Used Book in Good Condition
$24.99
Best Value

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.