Vulnerability Rediscovery on curl 8.3.0
2ASan Confirmed (T2)NeuroLog
Evaluation Results
| Method | Links | |
|---|---|---|
| NeuroLogCVE=CVE-2023-38545 (CVSS 9.8), Site=do_SOCKS5 async-yield: hostname OOB write past state.buffer, Detection rules (Datalog)=UnboundedServerWrite (project-specific Pass); JointBufferBoundUnsafe2026.05 | 2 | |
| NeuroLogFinding=curl SOCKS4 OOB, Site=do_SOCKS4 SOCKS4a: strcpy joint-bound miss (plen+hostnamelen>buffer_size), Detection rules (Datalog)=JointBufferBoundUnsafe (project-specific Pass)2026.05 | 2 | |
| NeuroLogFinding=curl WS heap OOB read, Site=ws_dec_read_head accepts MSB-set 64-bit payload_len → signed-to-unsigned OOB in ws_dec_pass_payload, Detection rules (Datalog)=TaintedSignExtension + TaintedWidthMismatchAtSink2026.05 | 2 |