CURL-CVE-2018-16840

Source
https://curl.se/docs/CVE-2018-16840.html
Import Source
https://curl.se/docs/CURL-CVE-2018-16840.json
JSON Data
https://api.osv.dev/v1/vulns/CURL-CVE-2018-16840
Aliases
Published
2018-10-31T08:00:00Z
Modified
2026-05-27T02:29:24Z
Summary
use after free in handle close
Details

libcurl contains a heap use after free flaw in code related to closing an easy handle.

When closing and cleaning up an "easy" handle in the Curl_close() function, the library code first frees a struct (without clearing the pointer) and might then subsequently erroneously write to a struct field within that already freed struct.

Database specific
{
    "CWE":  {
        "desc":  "Use After Free",
        "id":  "CWE-416"
    },
    "URL":  "https://curl.se/docs/CVE-2018-16840.json",
    "affects":  "both",
    "award":  {
        "amount":  "100",
        "currency":  "USD"
    },
    "last_affected":  "7.61.1",
    "package":  "curl",
    "severity":  "Low",
    "www":  "https://curl.se/docs/CVE-2018-16840.html"
}
Credits
    • Brian Carpenter (Geeknik Labs) - FINDER
    • Daniel Stenberg - REMEDIATION_DEVELOPER

Affected packages

Git / github.com/curl/curl.git

Affected ranges

Type
SEMVER
Events
Introduced
7.59.0
Fixed
7.62.0
Type
GIT
Repo
https://github.com/curl/curl.git
Events

Affected versions

7.*
7.59.0
7.60.0
7.61.0
7.61.1
Other
curl-7_59_0
curl-7_60_0
curl-7_61_0
curl-7_61_1

Database specific

source
"https://curl.se/docs/CURL-CVE-2018-16840.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "76450436232552618053190577593466383274",
                "56283251733270634435040735386618773715",
                "225146506795074944162099681821124504277",
                "72162716836877692358628916813877661635",
                "28202728034268574745574819732142521908"
            ],
            "threshold":  0.9
        },
        "id":  "CURL-CVE-2018-16840-a87c499d",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/curl/curl.git/commit/81d135d67155c5295b1033679c606165d4e28f3f",
        "target":  {
            "file":  "lib/url.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "253867143457341161698845574111827314122",
            "length":  1388
        },
        "id":  "CURL-CVE-2018-16840-ba2aaffc",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/curl/curl.git/commit/81d135d67155c5295b1033679c606165d4e28f3f",
        "target":  {
            "file":  "lib/url.c",
            "function":  "Curl_close"
        }
    }
]
vanir_signatures_modified
"2026-05-27T02:29:24Z"