CVE-2024-2398: Apple macOS

High severity, CVSS 8.6. EPSS: 36.1% chance of exploitation in the next 30 days.

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

Affected products

  • Apple macOS: before 12.7.6 (fixed in 12.7.6); from 13.0, before 13.6.8 (fixed in 13.6.8); from 14.0, before 14.6 (fixed in 14.6)
  • Fedoraproject Fedora: version 39 only; version 40 only
  • Haxx Curl: from 7.44.0, before 8.7.0 (fixed in 8.7.0)
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Bootstrap OS: affected versions not specified
  • Netapp Brocade Fabric Operating System: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h610c Firmware: affected versions not specified
  • Netapp h610s Firmware: affected versions not specified
  • Netapp h615c Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified

Published 2024-03-27. Last modified 2026-06-17.