Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:5654 - Security Advisory
Issued:
2024-08-20
Updated:
2024-08-20

RHSA-2024:5654 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: curl security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for curl is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: HTTP/2 push headers memory-leak (CVE-2024-2398)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2270498 - CVE-2024-2398 curl: HTTP/2 push headers memory-leak
  • RHEL-44684 - Incorrect backport of BZ 2229800 introduced in 8.10 curl

CVEs

  • CVE-2024-2398

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
curl-7.61.1-34.el8_10.2.src.rpm SHA-256: 041ce8183798bc2a0df672adf54830ab71cbf73474233d8a0818eda07f4d0df7
x86_64
curl-7.61.1-34.el8_10.2.x86_64.rpm SHA-256: fd49d8909651088750bf41693dd17aa836755fc526ef361605150654b9654d62
curl-debuginfo-7.61.1-34.el8_10.2.i686.rpm SHA-256: 1ea18407bef8076d46003f63cc4728db65c8f045b3d9d5629d8c9ec3c7f277e9
curl-debuginfo-7.61.1-34.el8_10.2.x86_64.rpm SHA-256: 6b4f14c1fb656e5a82e81bc808ccfe6139f337ce3759bcea8bd0dee261435bef
curl-debugsource-7.61.1-34.el8_10.2.i686.rpm SHA-256: c9b45d276bf4e32acddfcc67e195e95a50c97502d59539c2e2e678a735d11430
curl-debugsource-7.61.1-34.el8_10.2.x86_64.rpm SHA-256: 899c4539a3179cf9e6b5886071e2248cb67b83aafbec435a0ce704b6bda7ec42
curl-minimal-debuginfo-7.61.1-34.el8_10.2.i686.rpm SHA-256: 19651a597c4ca58e48385243f4aed0526c100b47f54f5efd82691c64814cece3
curl-minimal-debuginfo-7.61.1-34.el8_10.2.x86_64.rpm SHA-256: 021f83ac5c40408faa9e2de1e487a2ae13841ebde8b33538cbf9d1b21ea2abc7
libcurl-7.61.1-34.el8_10.2.i686.rpm SHA-256: 1cc8de37e5417bd44b2d795b03346dcbe23bbdab8c24085eb5f3379577a5efb5
libcurl-7.61.1-34.el8_10.2.x86_64.rpm SHA-256: 859068cf8231e01a044971b7a46de6d3ea9e00fec431f64f4406992e5a1a054f
libcurl-debuginfo-7.61.1-34.el8_10.2.i686.rpm SHA-256: 1c414c3a5bc310b0dc02dfe3995bcb470964d697531db6db5ac51b838b1bdc86
libcurl-debuginfo-7.61.1-34.el8_10.2.x86_64.rpm SHA-256: b6d1c8f5a67998181b24350dd7328df84563583ecf3087d14bc49a8a30f6ef43
libcurl-devel-7.61.1-34.el8_10.2.i686.rpm SHA-256: 26ee23f1e2fcf24f657cb2a88dab440b901bd87f2b6640a1ec3295d7b96d5681
libcurl-devel-7.61.1-34.el8_10.2.x86_64.rpm SHA-256: 4df99cf5f89a73bb8e93d39193604a6cabff21541cedb1702e3f288d20f77e0f
libcurl-minimal-7.61.1-34.el8_10.2.i686.rpm SHA-256: c7663782aaa17b0366afb34498be61790d0dbb67592662dbde6813384ab7cff1
libcurl-minimal-7.61.1-34.el8_10.2.x86_64.rpm SHA-256: 84975d14fc6b4cb76a952f4b313be1bc6124af43d0bb5c0eac2fa9ea1224cede
libcurl-minimal-debuginfo-7.61.1-34.el8_10.2.i686.rpm SHA-256: e35e994f7295ce99017195149d7408ab5350423c6d84238470cc7ced1d0eb9cb
libcurl-minimal-debuginfo-7.61.1-34.el8_10.2.x86_64.rpm SHA-256: d0eb97e870fe94c878a8c06d8b582a585c876b04d38ff5cf2651136d77c040e5

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
curl-7.61.1-34.el8_10.2.src.rpm SHA-256: 041ce8183798bc2a0df672adf54830ab71cbf73474233d8a0818eda07f4d0df7
s390x
curl-7.61.1-34.el8_10.2.s390x.rpm SHA-256: abbbe8d435af8eb19dc39f732cc80e414f35d5d337a9ac982eb869f4adfa83f8
curl-debuginfo-7.61.1-34.el8_10.2.s390x.rpm SHA-256: 1337593d4ee624f306a158e98dce357fc76deb84c31e418638a8cbb71cb88d07
curl-debugsource-7.61.1-34.el8_10.2.s390x.rpm SHA-256: bbda0718eadaa45d65081e388f83c927a41b078ef8ddd7c237c00dd97cb87be8
curl-minimal-debuginfo-7.61.1-34.el8_10.2.s390x.rpm SHA-256: c68dc9a2c4b95a90d2e55b57e0be724bf998d16ce1018b4a9a6afba8665ae787
libcurl-7.61.1-34.el8_10.2.s390x.rpm SHA-256: 69899d162bea58efddeadd64af8945d4f2764fdbdbb7c9b47eea281d430873cd
libcurl-debuginfo-7.61.1-34.el8_10.2.s390x.rpm SHA-256: b5d20fc16dc2fb62ba741cde67b92d5ed77606b29afd8f4668c8e092c13ef443
libcurl-devel-7.61.1-34.el8_10.2.s390x.rpm SHA-256: 813d182786b5e97ed6e00014c7453b9baab8629fb4d6a2fd9e31f6850fb4e27b
libcurl-minimal-7.61.1-34.el8_10.2.s390x.rpm SHA-256: 5f21413329b11cbae6281dd19f1d5e2a22eb5cd09e88204e6ac481643be05a44
libcurl-minimal-debuginfo-7.61.1-34.el8_10.2.s390x.rpm SHA-256: 4c50130552e345b83240984844110e4c02be921a8189dbcd1a2dc8cb72be159f

Red Hat Enterprise Linux for Power, little endian 8

SRPM
curl-7.61.1-34.el8_10.2.src.rpm SHA-256: 041ce8183798bc2a0df672adf54830ab71cbf73474233d8a0818eda07f4d0df7
ppc64le
curl-7.61.1-34.el8_10.2.ppc64le.rpm SHA-256: 69c743bf21918a48a764359c33e23cc0ffc4d5fd690597dad5808a3e905ac6f7
curl-debuginfo-7.61.1-34.el8_10.2.ppc64le.rpm SHA-256: 508172b816f409d4e2b7ec9bcf6df23f16dd06c053a7f4e2b9de0e842fd43c33
curl-debugsource-7.61.1-34.el8_10.2.ppc64le.rpm SHA-256: de66acd4e71faa7b4d019ef564b4198c5463fe813c41485eb0ad924adc676f8f
curl-minimal-debuginfo-7.61.1-34.el8_10.2.ppc64le.rpm SHA-256: de7150ca425d1e1f0c9df3483fb20ac74237aca7bd5acba3aaafff5a654e91bb
libcurl-7.61.1-34.el8_10.2.ppc64le.rpm SHA-256: 3853cf60f50904769fe87732e030ff4c39df2616b524eb44f1b7c28ca127c3df
libcurl-debuginfo-7.61.1-34.el8_10.2.ppc64le.rpm SHA-256: cf4c3e811d2b0a67a09301c99db3d7381769a3e71bd9d761f6b461b1e7153907
libcurl-devel-7.61.1-34.el8_10.2.ppc64le.rpm SHA-256: 9224533fdbef5ce2a0c548f67d006d1939e952ad04e02f945871bb8d9c82f76d
libcurl-minimal-7.61.1-34.el8_10.2.ppc64le.rpm SHA-256: d3bf41a18df362ba4076e5d04812bf75403040d61a6116eba8a796893357f63d
libcurl-minimal-debuginfo-7.61.1-34.el8_10.2.ppc64le.rpm SHA-256: 1311b87c38d9f6974503b0ccf41a8d9eeb0416a0459edcd3b7b63d2ec75d711d

Red Hat Enterprise Linux for ARM 64 8

SRPM
curl-7.61.1-34.el8_10.2.src.rpm SHA-256: 041ce8183798bc2a0df672adf54830ab71cbf73474233d8a0818eda07f4d0df7
aarch64
curl-7.61.1-34.el8_10.2.aarch64.rpm SHA-256: f170d758299671a70b2c27f5ddb7b756f909b08c1f9e1654028f7803f661a112
curl-debuginfo-7.61.1-34.el8_10.2.aarch64.rpm SHA-256: d3819ca0372b111d585bc4509b21dc965056c6fec07dddead17b12ab6348bbc2
curl-debugsource-7.61.1-34.el8_10.2.aarch64.rpm SHA-256: 7d0ed077e7eb4dfa62e47e97bd7a8ad50816a762522afa83d61c792efeee4927
curl-minimal-debuginfo-7.61.1-34.el8_10.2.aarch64.rpm SHA-256: 6a4de6b90db3ec7ec755c54e5ffa50e2ef90961ac18c3844d77c6b3ea43e8601
libcurl-7.61.1-34.el8_10.2.aarch64.rpm SHA-256: d29630ebc1b2c3d3cb7f329321eef989bab7f4756e9851f82625dc81c289f933
libcurl-debuginfo-7.61.1-34.el8_10.2.aarch64.rpm SHA-256: 5e30f4fc9b5e942916cbee4f4b101c938fb424910658030d56474bf8fbb28376
libcurl-devel-7.61.1-34.el8_10.2.aarch64.rpm SHA-256: d45fe806eeefed44938a5d31b44a21d522a6d48c78247855f87a4cd6f8ddd095
libcurl-minimal-7.61.1-34.el8_10.2.aarch64.rpm SHA-256: 0628ebcc00dd2a7251a5eb0d160b1f678564f1526546641657d9105ab5988dc3
libcurl-minimal-debuginfo-7.61.1-34.el8_10.2.aarch64.rpm SHA-256: c39ca32e1e0c0b78b3fa5808d102578a296e838778897fc0ecb0becf4c3912cf

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility