CVE-2024-6232

Aliases:DEBIAN-CVE-2024-6232RHSA-2024:7647RHSA-2024:8130RHSA-2024:8359RHSA-2024:8374RHSA-2024:8446RHSA-2024:8447RHSA-2024:8490RHSA-2024:8504RHSA-2024:8797RHSA-2024:8836RHSA-2024:8838RHSA-2024:8977RHSA-2024:9450RHSA-2024:9451RHSA-2024:9468RHSA-2025:1750ALPINE-CVE-2024-6232CGA-33qr-rjjx-3f4cCGA-642x-x8q6-7p68CGA-g393-cmw5-f8m2CGA-44ww-mpwv-g464CGA-qmpp-4j4v-4rq8CGA-qrvq-hmj4-v72vCGA-rq3j-j6m4-f89rCGA-v9gr-6fhv-w765CGA-x2fv-248j-gp5gCGA-xv6w-2vg6-4wr8
Advisory lineage Upstream: 0 Downstream: 50
Modified
Published: 03 Sept 2024, 12:29
Last modified:03 Nov 2025, 22:32

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
2.2% LOW
2% probability -0.97%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

03 Sept 2024, 12:29
Published
Vulnerability first disclosed
03 Nov 2025, 22:32
Last Modified
Vulnerability information updated

Description

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 2.20% Percentile: 82%

Techniques & Countermeasures

  • CWE-1333Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Systems

  • alpinepython3

    < 3.10.15-r0 | < 3.11.10-r0 | < 3.11.10-r0 | < 3.12.6-r0 | < 3.12.6-r0 | < 3.12.6-r0 | < 3.12.6-r0 | < 3.12.6-r0

  • chainguardpython-3.10

    < 3.10.15-r0

  • chainguardpython-3.11

    < 3.11.9-r9

  • chainguardpython-3.12

    < 3.12.5-r3

  • chainguardpython-3.13

    < 3.13.2-r6

  • chainguardpython-3.9

    < 3.9.20-r0

  • wolfipython-3.10

    < 3.10.15-r0

  • wolfipython-3.11

    < 3.11.9-r9

  • wolfipython-3.12

    < 3.12.5-r3

  • wolfipython-3.13

    < 3.13.2-r6

  • debianpypy3

    < 7.3.5+dfsg-2+deb11u5 | all | < 7.3.18+dfsg-1 | < 7.3.18+dfsg-1

  • debianpython2.7

    all

  • debianpython3.11

    < 3.11.2-6+deb12u4

  • debianpython3.13

    < 3.13.0~rc2-1 | < 3.13.0~rc2-1

  • debianpython3.9

    < 3.9.2-1+deb11u2

  • python software foundationcpython

    < 3.8.20 | ≥ 3.9.0, < 3.9.20 | ≥ 3.10.0, < 3.10.15 | ≥ 3.11.0, < 3.11.10 | ≥ 3.12.0, < 3.12.6 | ≥ 3.13.0a1, < 3.13.0rc2

  • pythonpython

    < 3.8.20 | ≥ 3.9.0, < 3.9.20 | ≥ 3.10.0, < 3.10.15 | ≥ 3.11.0, < 3.11.10 | ≥ 3.12.0, < 3.12.6 | 3.13.0:alpha0 | 3.13.0:alpha1 | 3.13.0:alpha2 | 3.13.0:alpha3 | 3.13.0:alpha4 | 3.13.0:alpha5 | 3.13.0:alpha6 | 3.13.0:beta1 | 3.13.0:beta2 | 3.13.0:beta3 | 3.13.0:beta4 | 3.13.0:rc1

  • redhatCython

    < 0:0.29.21-5.module+el8.9.0+19644+d68f775d

  • redhatCython-debugsource

    < 0:0.29.21-5.module+el8.9.0+19644+d68f775d

  • redhatmod_wsgi

    < 0:4.7.1-7.module+el8.9.0+19644+d68f775d | < 0:4.7.1-5.module+el8.7.0+16654+645aad7f | < 0:4.7.1-4.module+el8.4.0+9822+20bf1249

  • redhatnumpy

    < 0:1.19.4-3.module+el8.9.0+19644+d68f775d | < 0:1.19.4-3.module+el8.5.0+12204+54860423 | < 0:1.19.4-2.module+el8.4.0+15042+dc5a279b.1

  • redhatnumpy-debugsource

    < 0:1.19.4-3.module+el8.9.0+19644+d68f775d | < 0:1.19.4-3.module+el8.5.0+12204+54860423 | < 0:1.19.4-2.module+el8.4.0+15042+dc5a279b.1

  • redhatpybind11

    < 0:2.7.1-1.module+el8.9.0+19644+d68f775d

  • redhatpytest

    < 0:6.0.2-2.module+el8.9.0+19644+d68f775d

  • redhatpython-attrs

    < 0:20.3.0-2.module+el8.9.0+19644+d68f775d

  • redhatpython-cffi

    < 0:1.14.3-2.module+el8.9.0+19644+d68f775d | < 0:1.14.3-2.module+el8.4.0+9822+20bf1249

  • redhatpython-cffi-debugsource

    < 0:1.14.3-2.module+el8.9.0+19644+d68f775d | < 0:1.14.3-2.module+el8.4.0+9822+20bf1249

  • redhatpython-chardet

    < 0:3.0.4-19.module+el8.9.0+19644+d68f775d | < 0:3.0.4-19.module+el8.4.0+9822+20bf1249

  • redhatpython-cryptography

    < 0:3.3.1-3.module+el8.10.0+21271+eccd1d86 | < 0:3.3.1-2.module+el8.4.0+9822+20bf1249

  • redhatpython-cryptography-debugsource

    < 0:3.3.1-3.module+el8.10.0+21271+eccd1d86 | < 0:3.3.1-2.module+el8.4.0+9822+20bf1249

  • redhatpython-idna

    < 0:2.10-4.module+el8.10.0+21815+bb024982 | < 0:2.10-3.module+el8.4.0+9822+20bf1249

  • redhatpython-iniconfig

    < 0:1.1.1-2.module+el8.9.0+19644+d68f775d

  • redhatpython-lxml

    < 0:4.6.5-1.module+el8.9.0+19644+d68f775d | < 0:4.6.5-1.module+el8.6.0+13933+9cf0c87c | < 0:4.6.2-2.module+el8.4.0+9822+20bf1249

  • redhatpython-lxml-debugsource

    < 0:4.6.5-1.module+el8.9.0+19644+d68f775d | < 0:4.6.5-1.module+el8.6.0+13933+9cf0c87c | < 0:4.6.2-2.module+el8.4.0+9822+20bf1249

  • redhatpython-more-itertools

    < 0:8.5.0-2.module+el8.9.0+19644+d68f775d

  • redhatpython-packaging

    < 0:20.4-4.module+el8.9.0+19644+d68f775d

  • redhatpython-pluggy

    < 0:0.13.1-3.module+el8.9.0+19644+d68f775d

  • redhatpython-ply

    < 0:3.11-10.module+el8.9.0+19644+d68f775d | < 0:3.11-10.module+el8.4.0+9822+20bf1249

  • redhatpython-psutil

    < 0:5.8.0-4.module+el8.9.0+19644+d68f775d | < 0:5.8.0-4.module+el8.4.0+9822+20bf1249

  • redhatpython-psutil-debugsource

    < 0:5.8.0-4.module+el8.9.0+19644+d68f775d | < 0:5.8.0-4.module+el8.4.0+9822+20bf1249

  • redhatpython-psycopg2

    < 0:2.8.6-3.module+el8.10.0+21142+453d2b75 | < 0:2.8.6-2.module+el8.4.0+9822+20bf1249

  • redhatpython-psycopg2-debugsource

    < 0:2.8.6-3.module+el8.10.0+21142+453d2b75 | < 0:2.8.6-2.module+el8.4.0+9822+20bf1249

  • redhatpython-py

    < 0:1.10.0-1.module+el8.9.0+19644+d68f775d

  • redhatpython-pycparser

    < 0:2.20-3.module+el8.9.0+19644+d68f775d | < 0:2.20-3.module+el8.4.0+9822+20bf1249

  • redhatpython-PyMySQL

    < 0:0.10.1-2.module+el8.9.0+19644+d68f775d | < 0:0.10.1-2.module+el8.4.0+9822+20bf1249

  • redhatpython-pysocks

    < 0:1.7.1-4.module+el8.9.0+19644+d68f775d | < 0:1.7.1-4.module+el8.4.0+9822+20bf1249

  • redhatpython-requests

    < 0:2.25.0-3.module+el8.9.0+19644+d68f775d | < 0:2.25.0-2.module+el8.4.0+9822+20bf1249

  • redhatpython-toml

    < 0:0.10.1-5.module+el8.9.0+19644+d68f775d | < 0:0.10.1-5.module+el8.4.0+9822+20bf1249

  • redhatpython-unversioned-command

    < 0:3.9.10-4.el9_0.6 | < 0:3.9.18-3.el9_4.6 | < 0:3.9.19-8.el9_5.1

  • redhatpython-urllib3

    < 0:1.25.10-5.module+el8.10.0+20443+f0a692fe | < 0:1.25.10-4.module+el8.5.0+11712+ea2d2be1 | < 0:1.25.10-3.module+el8.4.0+9822+20bf1249

Showing first 50 affected entries in server-rendered view.

References (54)