Mageia 2024-0317: python3 Security Advisory Updates
Summary
A defect was discovered in the Python âsslâ module where there is a memory race condition with the ssl.SSLContext methods âcert_store_stats()â and âget_ca_certs()â. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. (CVE-2024-0397) The âipaddressâ module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as âglobally reachableâ or âprivateâ. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldnât be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. (CVE-2024-4032) The email module didnât properly quote newlines for email headers when serializing ...
Read the Full AdvisoryReferences
- https://bugs.mageia.org/show_bug.cgi?id=33436
- https://www.openwall.com/lists/oss-security/2024/06/17/2
- https://www.openwall.com/lists/oss-security/2024/06/17/3
- https://lwn.net/Articles/983060/
- https://www.openwall.com/lists/oss-security/2024/08/01/3
- https://www.openwall.com/lists/oss-security/2024/08/22/1
- https://www.openwall.com/lists/oss-security/2024/09/03/5
- https://www.openwall.com/lists/oss-security/2024/09/07/3
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0397
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4032
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6923
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8088
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6232
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7592
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2104
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27043
Resolution
MGASA-2024-0317 - Updated python3 packages fix security vulnerabilities
SRPMS
- 9/core/python3-3.10.11-1.3.mga9