Nixpkgs security tracker

Login with GitHub

Suggestion detail

Untriaged
created 1 month ago Activity log
  • Created suggestion
Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes

The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected.

Affected products

CPython
  • <3.15.0

Matching in nixpkgs

Package maintainers