The vendor has not yet reached a final affected or unaffected determination for these products.
- build-of-trustee/trustee-rhel9 as a component of Confidential Compute Attestation
- openshift-sandboxed-containers/osc-podvm-payload-rhel9 as a component of Confidential Compute Attestation
- cargo as a component of Red Hat Enterprise Linux 10
- clippy as a component of Red Hat Enterprise Linux 10
- igvm.src as a component of Red Hat Enterprise Linux 10
- rust-analyzer as a component of Red Hat Enterprise Linux 10
- rust-debugger-common as a component of Red Hat Enterprise Linux 10
- rust-doc as a component of Red Hat Enterprise Linux 10
- rust-gdb as a component of Red Hat Enterprise Linux 10
- rust-lldb as a component of Red Hat Enterprise Linux 10
- rust-src as a component of Red Hat Enterprise Linux 10
- rust-std-static as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in libcurl. When `curl_easy_pause()` is called within the event-based `CURLMOPT_SOCKETFUNCTION` callback, a use-after-free vulnerability is triggered. This occurs because libcurl attempts to store a flag using a pointer to memory that has already been freed. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
