Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 894676 (CVE-2023-23914, CVE-2023-23915, CVE-2023-23916) - <net-misc/curl-7.88.0: Multiple vulnerabilities
Summary: <net-misc/curl-7.88.0: Multiple vulnerabilities
Alias: CVE-2023-23914, CVE-2023-23915, CVE-2023-23916
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
Whiteboard: A3 [glsa?]
Keywords: PullRequest
Depends on:
Reported: 2023-02-16 05:36 UTC by Matt Jolly
Modified: 2023-04-07 05:06 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Matt Jolly 2023-02-16 05:36:07 UTC
Multiple CVEs in cURL <7.88.0

Reproducible: Always
Comment 1 Matt Jolly 2023-02-16 05:46:19 UTC
See (though there's not much info):

cURL 7.88.0 is currently masked due to HTTP/2 issues. I'll keep an eye on upstream and either apply patches to unmask or bump the package if there's a new release.
Comment 2 Larry the Git Cow gentoo-dev 2023-02-17 05:13:58 UTC
The bug has been referenced in the following commit(s):

commit 04f8286d4a957947b08a02402a6ca6c8f949e26e
Author:     Matt Jolly <>
AuthorDate: 2023-02-16 10:14:47 +0000
Commit:     Sam James <>
CommitDate: 2023-02-17 05:09:07 +0000

    net-misc/curl: add 7.88.0-r1
    * Add HTTP/2 patchset
    * Add test fix patchset
    Signed-off-by: Matt Jolly <>
    Signed-off-by: Sam James <>

 net-misc/curl/curl-7.88.0-r1.ebuild         | 298 ++++++++++++++++++++++++++++
 net-misc/curl/files/curl-7.88.0-http2.patch |  93 +++++++++
 net-misc/curl/files/curl-7.88.0-tests.patch | 120 +++++++++++
 3 files changed, 511 insertions(+)
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-02-20 20:44:56 UTC