yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-46219
Component Overview
Vulnerability Overview
Name
CVE-2023-46219
Source
NVD (
link
)
Debian (
link
)
Description
When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.
CWEs
CWE-311
CWE-311
Published Date
Dec 12, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://curl.se/docs/CVE-2023-46219.html
Vendor Advisory
https://hackerone.com/reports/2236133
Exploit
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UOGXU25FMMT2X6UUITQ7EZZYMJ42YWWD/
Third Party Advisory
https://curl.se/docs/CVE-2023-46219.html
Vendor Advisory
https://hackerone.com/reports/2236133
Exploit
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UOGXU25FMMT2X6UUITQ7EZZYMJ42YWWD/
Third Party Advisory
Analysis
#
Affected Component
Analysis
curl
Patched
Vulnerability Ratings
#
5.3
CVSSv31
5.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libcurl
buildroot
2025.02.x
8.20.0
Not Affected
libcurl
buildroot
master
8.21.0
Not Affected
curl
openwrt
master
8.19.0-r2
Not Affected
libcurl-gnutls
openwrt
master
8.20.0-r1
Not Affected
curl
openwrt
openwrt-25.12
8.19.0-r2
Not Affected
libcurl-gnutls
openwrt
openwrt-25.12
8.14.1-r1
Not Affected
curl
yocto
master
8.20.0
Not Affected
curl
yocto
scarthgap
8.7.1
Not Affected
Resolved with patches
#
curl (yocto:kirkstone)
#
Title
Author
Resolve
1
fopen: allocate the dir after fopen
Daniel Stenberg <daniel@haxx.se>
CVE-2023-46219
2
fopen: create short(er) temporary file name
Daniel Stenberg <daniel@haxx.se>
CVE-2023-46219
3
fopen: optimize
SaltyMilk <soufiane.elmelcaoui@gmail.com>
CVE-2023-46219