Race condition In pypy3
Description
A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 7.3.16+dfsg-1 | ||
debian 12 | - | ||
debian 14 | 7.3.16+dfsg-1 | ||
debian 12 | 3.11.2-6+deb12u3 | ||
rpm rhel7 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | 0:3.11.9-7.el9 | ||
rpm rhel8 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | 0:3.9.21-1.el9_5 |
1-10 of 16
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.