KEMBAR78
python-3.10/3.11/CVE-2023-38898 advisory update by jamie-albert · Pull Request #8607 · wolfi-dev/advisories · GitHub
Skip to content

Conversation

@jamie-albert
Copy link
Member

This CVE is claimed to be inaccurate and is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases and up); (2) there are no common scenarios in which an adversary can call _asyncio._swap_current_task but does not already have the ability to call arbitrary functions; and (3) there are no common scenarios in which sensitive information, which is not already accessible to an adversary, becomes accessible through this bug. Affected versions can be found under the tags here in this commit and PR that resolved the bug here

…ontested

Signed-off-by: jamie-albert <jamie.albert@chainguard.dev>
Signed-off-by: jamie-albert <jamie.albert@chainguard.dev>
…ontested

Signed-off-by: jamie-albert <jamie.albert@chainguard.dev>
@powersj powersj assigned powersj and jamie-albert and unassigned powersj Oct 10, 2024
@jamie-albert jamie-albert added this pull request to the merge queue Oct 10, 2024
Merged via the queue into wolfi-dev:main with commit 1e85433 Oct 10, 2024
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Crash in _asyncio._swap_current_task due to improper reference counting

4 participants