We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local connected pair of sockets. The connection between the two sockets was not verified before passing the two sockets back to the user, which leaves the server socket vulnerable to a connection race from a malicious local peer. Platforms that support AF_UNIX such as Linux and macOS are not affected by this vulnerability. Versions prior to CPython 3.5 are not affected due to the vulnerable API not being included.
Reserved 2024-04-02 | Published 2024-07-29 | Updated 2024-11-04 | Assigner PSFEllie
github.com/python/cpython/pull/122134
github.com/python/cpython/issues/122133
mail.python.org/.../thread/WYKDQWIERRE2ICIYMSVRZJO33GSCWU2B/
www.openwall.com/lists/oss-security/2024/07/29/3
github.com/...ommit/06fa244666ec6335a3b9bf2367e31b42b9a89b20
github.com/...ommit/0b65c8bf5367625673eafb92f85046a1b31259f2
github.com/...ommit/220e31adeaaa8436c9ff234cba1398bc49e2bb6c
github.com/...ommit/5f90abaa786f994db3907fc31e2ee00ea2cf0929
github.com/...ommit/b252317956b7fc035bb3774ef6a177e227f9fc54
github.com/...ommit/2621a8a40ba4b2c68ca564671b7daa5da80a4508
github.com/...ommit/5df322e91a40909e6904bbdbc0c3a6b6a9eead39
github.com/...ommit/c21a36112a0028d7ac3cf8f480e0dc88dba5922c
github.com/...ommit/f071f01b7b7e19d7d6b3a4b0ec62f820ecb14660
github.com/...ommit/31302f5fc24eecd693f0c8aaba7c2840b09b594d
github.com/...ommit/3f5d9d12c74787fbf3f5891835c85cc15526c86d
github.com/...ommit/c5655aa6ad120d2ed7f255bebd6e8b71a9c07dde
github.com/...ommit/e319f774f9e766a2b92949444a2d46081df3363a
Support options