CVE & CISA-KEV Catalog

CVE-2023-38545

CRITICALEPSS 100th pctl
9.8
CVSS v3
NVD

Description

This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.

How to fix

Remediation Available
curlDebian
Fixed in:7.74.0-1.3+deb11u10CVE-2023-38545
Fixed in:7.88.1-10+deb12u4CVE-2023-38545
Fixed in:8.3.0-3CVE-2023-38545
Fixed in:8.3.0-3CVE-2023-38545
Windows 10 Version 1809Windows
Install:KB5032196Microsoft
Windows 10 Version 21H2Windows
Install:KB5032189Microsoft
Install:KB5032192Microsoft
Windows 10 Version 22H2Windows
Install:KB5032189Microsoft
Windows 11 Version 22H2Windows
Install:KB5032190Microsoft
Windows 11 Version 23H2Windows
Install:KB5032190Microsoft
Windows 11 version 21H2Windows
Install:KB5032192Microsoft
Windows Server 2019Windows
Install:KB5032196Microsoft
Windows Server 2019 (Server Core installation)Windows
Install:KB5032196Microsoft
Windows Server 2022Windows
Install:KB5032198Microsoft
Windows Server 2022 (Server Core installation)Windows
Install:KB5032198Microsoft
candlepinRed Hat / RHEL
Fixed in:0:4.3.11-1.el8satRHSA-2024:0797
Fixed in:0:4.3.11-1.el8satRHSA-2024:0797
candlepinRocky
Fixed in:0:4.3.11-1.el8satRHSA-2024:0797
Fixed in:0:4.3.11-1.el8satRHSA-2024:0797
candlepin-selinuxRocky
Fixed in:0:4.3.11-1.el8satRHSA-2024:0797
candlepin-selinuxRed Hat / RHEL
Fixed in:0:4.3.11-1.el8satRHSA-2024:0797
curlRocky
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
curlRed Hat / RHEL
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
curl-debuginfoRed Hat / RHEL
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
curl-debuginfoRocky
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
curl-debugsourceRed Hat / RHEL
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
curl-debugsourceRocky
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
curl-minimalRocky
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
curl-minimalRed Hat / RHEL
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
curl-minimal-debuginfoRed Hat / RHEL
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
curl-minimal-debuginfoRocky
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
Fixed in:0:7.76.1-14.el9_0.9RHSA-2023:5700
Fixed in:0:7.76.1-26.el9_3.2RHSA-2023:6745
Fixed in:0:7.76.1-23.el9_2.4RHSA-2023:5763
foremanRocky
Fixed in:0:3.7.0.11-2.el8satRHSA-2024:0797
Fixed in:0:3.7.0.11-2.el8satRHSA-2024:0797
foremanRed Hat / RHEL
Fixed in:0:3.7.0.11-2.el8satRHSA-2024:0797
Fixed in:0:3.7.0.11-2.el8satRHSA-2024:0797
foreman-cliRocky
Fixed in:0:3.7.0.11-2.el8satRHSA-2024:0797
foreman-cliRed Hat / RHEL
Fixed in:0:3.7.0.11-2.el8satRHSA-2024:0797
foreman-debugRocky
Fixed in:0:3.7.0.11-2.el8satRHSA-2024:0797

This vulnerability affects an unusually large number of packages. The highest-confidence fixes are shown above; the full list is longer. Check the referenced advisories for complete coverage.

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Intelligence

78.48%probability of exploitation in 30 days
100thpercentile

Very high risk: more likely to be exploited than 100% of all known CVEs.

References

Related Vulnerabilities

Other CWE-787 (Out-of-bounds Write) vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2025-22457Critical9.0100%KEV + RansomFix
CVE-2025-0282Critical9.0100%KEV + Ransom-
CVE-2023-4863High8.8100%KEVFix
CVE-2015-3113Critical9.8100%KEVFix
CVE-2021-20038Critical9.8100%KEV + Ransom-
CVE-2019-11043High8.7100%KEV + RansomFix

Common questions

How do I fix CVE-2023-38545?

Published advisories record a fix for 239 affected products. The "How to fix" section on this page lists the fixed version and source advisory for each one, so apply the entry matching what you actually run.

Is CVE-2023-38545 being actively exploited?

Not that we know of. CVE-2023-38545 is not in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 78.5% is the estimated probability that it will be exploited in the next 30 days. That is higher than 100% of all scored CVEs.

How severe is CVE-2023-38545?

CVE-2023-38545 has a CVSS v3 base score of 9.8, rated critical. CVSS rates the technical impact if the vulnerability is exploited, not how likely that is, so weigh it alongside the exploit-prediction score when you decide what to patch first.

What does CVE-2023-38545 affect?

Published advisories record a fix for curl (Debian), Windows 10 Version 1809 (Windows), Windows 10 Version 21H2 (Windows), Windows 10 Version 22H2 (Windows), and 235 more. Only products with a sourced advisory are listed, so treat this as what we can cite rather than a complete inventory.

Embed a live status badge for CVE-2023-38545
CVE-2023-38545 severity badge

Markdown

[![CVE-2023-38545](https://tridentstack.com/cve/badge/CVE-2023-38545.svg)](https://tridentstack.com/cve/CVE-2023-38545)

HTML

<a href="https://tridentstack.com/cve/CVE-2023-38545"><img src="https://tridentstack.com/cve/badge/CVE-2023-38545.svg" alt="CVE-2023-38545"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-05-12.