libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Fedoraproject Subscribe
Libcurl Subscribe
Cloud Backup Subscribe
Clustered Data Ontap Subscribe
Solidfire \& Hci Management Node Subscribe
Solidfire Baseboard Management Controller Firmware Subscribe
Mysql Server Subscribe
Peoplesoft Enterprise Peopletools Subscribe
Enterprise Linux Subscribe
Rhel Dotnet Subscribe
Siemens Subscribe
Logo\! Cmr2020 Subscribe
Logo\! Cmr2020 Firmware Subscribe
Logo\! Cmr2040 Subscribe
Logo\! Cmr2040 Firmware Subscribe
Ruggedcomrm 1224 Lte Subscribe
Ruggedcomrm 1224 Lte Firmware Subscribe
Scalance M804pb Subscribe
Scalance M804pb Firmware Subscribe
Scalance M812-1 Subscribe
Scalance M812-1 Firmware Subscribe
Scalance M816-1 Subscribe
Scalance M816-1 Firmware Subscribe
Scalance M826-2 Subscribe
Scalance M826-2 Firmware Subscribe
Scalance M874-2 Subscribe
Scalance M874-2 Firmware Subscribe
Scalance M874-3 Subscribe
Scalance M874-3 Firmware Subscribe
Scalance M876-3 Subscribe
Scalance M876-3 Firmware Subscribe
Scalance M876-4 Subscribe
Scalance M876-4 Firmware Subscribe
Scalance Mum856-1 Subscribe
Scalance Mum856-1 Firmware Subscribe
Scalance S615 Subscribe
Scalance S615 Firmware Subscribe
Simatic Cp 1543-1 Subscribe
Simatic Cp 1543-1 Firmware Subscribe
Simatic Cp 1545-1 Subscribe
Simatic Cp 1545-1 Firmware Subscribe
Simatic Rtu3010c Subscribe
Simatic Rtu3010c Firmware Subscribe
Simatic Rtu3030c Subscribe
Simatic Rtu3030c Firmware Subscribe
Simatic Rtu3031c Subscribe
Simatic Rtu3031c Firmware Subscribe
Simatic Rtu 3041c Subscribe
Simatic Rtu 3041c Firmware Subscribe
Sinec Infrastructure Network Services Subscribe
Sinema Remote Connect Subscribe
Sinema Remote Connect Server Subscribe
Siplus Net Cp 1543-1 Subscribe
Siplus Net Cp 1543-1 Firmware Subscribe
Universal Forwarder Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2734-1 curl security update
Debian DLA Debian DLA DLA-3085-1 curl security update
Debian DSA Debian DSA DSA-5197-1 curl security update
EUVD EUVD EUVD-2021-10053 libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
Ubuntu USN Ubuntu USN USN-5021-1 curl vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 09 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-06-09T15:02:19.721Z

Reserved: 2021-01-06T00:00:00.000Z

Link: CVE-2021-22924

cve-icon Vulnrichment

Updated: 2024-08-03T18:58:25.955Z

cve-icon NVD

Status : Modified

Published: 2021-08-05T21:15:11.380

Modified: 2025-06-09T15:15:24.403

Link: CVE-2021-22924

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-07-21T06:00:00Z

Links: CVE-2021-22924 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses