跳转到帖子

Alma Linux: CVE-2024-12254: Important: python3.12 security update (Multiple Advisories)

recommended_posts

发布于
  • Members

Alma Linux: CVE-2024-12254: Important: python3.12 security update (Multiple Advisories)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
12/06/2024
Created
12/20/2024
Added
12/19/2024
Modified
12/24/2024

Description

Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark". Because of this, Protocols would not periodically drain the write buffer potentially leading to memory exhaustion. This vulnerability likely impacts a small number of users, you must be using Python 3.12.0 or later, on macOS or Linux, using the asyncio module with protocols, and using .writelines() method which had new zero-copy-on-write behavior in Python 3.12.0 and later. If not all of these factors are true then your usage of Python is unaffected.

Solution(s)

  • alma-upgrade-python3.12
  • alma-upgrade-python3.12-debug
  • alma-upgrade-python3.12-devel
  • alma-upgrade-python3.12-idle
  • alma-upgrade-python3.12-libs
  • alma-upgrade-python3.12-rpm-macros
  • alma-upgrade-python3.12-test
  • alma-upgrade-python3.12-tkinter

References

  • https://attackerkb.com/topics/cve-2024-12254
  • CVE - 2024-12254
  • https://errata.almalinux.org/8/ALSA-2024-10980.html
  • https://errata.almalinux.org/9/ALSA-2024-10978.html
  • 查看数 697
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…