Untriaged
Permalink
CVE-2024-9979
5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): LOW
Pyo3: risk of use-after-free in `borrowed` reads from python weak references
A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or crashes via unsound borrowing from weak Python references.
References
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
- https://access.redhat.com/security/cve/CVE-2024-9979 x_refsource_REDHAT vdb-entry
- RHBZ#2318646 issue-tracking x_refsource_REDHAT
- https://crates.io/crates/pyo3
- https://github.com/PyO3/pyo3/pull/4590
- https://rustsec.org/advisories/RUSTSEC-2024-0378.html
Affected products
pyo3
- <0.22.4
python-rpds-py
python3.11-nh3
python3.11-rpds-py
python3.11-cryptography
python3.12-cryptography
Matching in nixpkgs
pkgs.python312Packages.cryptography
Package which provides cryptographic recipes and primitives
-
nixos-unstable -
- nixpkgs-unstable 45.0.4
Package maintainers
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>