Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
The bundled `curl` sources (via the Rust `curl-sys` crate) are wholly removed during the `%prep` phase to be sure we don't use them. Instead, we use the system `curl` library, so any CVE fixes only need to be made in that component on its own.