The vendor explicitly identifies these products or versions as containing the fix.
- curl-main@aarch64 as a component of Red Hat Hardened Images
- curl-main@src as a component of Red Hat Hardened Images
- curl-main@x86_64 as a component of Red Hat Hardened Images
- rust-main@aarch64 as a component of Red Hat Hardened Images
- rust-main@noarch as a component of Red Hat Hardened Images
- rust-main@src as a component of Red Hat Hardened Images
- rust-main@x86_64 as a component of Red Hat Hardened Images
- Summary
- A flaw was found in curl and libcurl. A malicious HTTP/3 server can exploit an issue in the QUIC UDP receive function by continuously streaming empty UDP datagrams. This can lead to a remote denial of service (DoS) against a curl or libcurl client, as the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, causing the client to indefinitely stall.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
