Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-0397

June 17, 2024, 6:15 p.m.

Product(s) Impacted

CPython

  • 3.10.14
  • 3.11.9
  • 3.12.3
  • 3.13.0a5

Description

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

Weaknesses

Date

Published: June 17, 2024, 4:15 p.m.

Last Modified: June 17, 2024, 6:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cna@python.org

References