python-psutil: Double free because of refcount mishandling
Published Nov 12, 2019
8.7
HIGHCVSS 4.0
EPSS 3.52%
Description
psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.
Affected products
No data.
- ≤ 5.6.5
No data.
Red Hat Ansible Tower 3.6 for RHEL 7
ansible-tower-36/ansible-runner-rhel7:1.4.4-2
Fixed · RHSA-2020:4255
Red Hat Ansible Tower 3.7 for RHEL 7
ansible-tower-37/ansible-runner-rhel7:1.4.6-2
Fixed · RHSA-2020:4254
Red Hat Ansible Tower 3.7 for RHEL 7
ansible-tower-37/ansible-tower-rhel7:3.7.4-1
Fixed · RHSA-2020:5249
Red Hat Enterprise Linux 8
python-psutil-0:5.4.3-11.el8
Fixed · RHSA-2021:4324
Red Hat Enterprise Linux 8
python38-devel:3.8-8050020210811101222.e3d35cca
Fixed · RHSA-2021:4162
Red Hat Enterprise Linux 8
python38:3.8-8050020210811101222.e3d35cca
Fixed · RHSA-2021:4162
Red Hat OpenShift Container Platform 4.2
python-psutil-0:5.6.6-1.el7ar
Fixed · RHSA-2020:2593
Red Hat OpenShift Container Platform 4.3
python-psutil-0:5.6.6-1.el7ar
Fixed · RHSA-2020:2635
Red Hat OpenShift Container Platform 4.4
python-psutil-0:5.6.6-1.el7ar
Fixed · RHSA-2020:2583
Red Hat Satellite 6.9 for RHEL 7
python-psutil-0:5.7.2-2.el7sat
Fixed · RHSA-2021:1313
Red Hat Satellite 6.9 for RHEL 7
python-psutil-0:5.7.2-2.el7sat
Fixed · RHSA-2021:1313
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-0:3.8.6-1.el7
Fixed · RHSA-2020:4299
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-psutil-0:5.6.4-5.el7
Fixed · RHSA-2020:4299
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-urllib3-0:1.25.7-6.el7
Fixed · RHSA-2020:4299
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-python38-python-0:3.8.6-1.el7
Fixed · RHSA-2020:4299
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-python38-python-psutil-0:5.6.4-5.el7
Fixed · RHSA-2020:4299
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-python38-python-urllib3-0:1.25.7-6.el7
Fixed · RHSA-2020:4299
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python38-python-0:3.8.6-1.el7
Fixed · RHSA-2020:4299
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python38-python-psutil-0:5.6.4-5.el7
Fixed · RHSA-2020:4299
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python38-python-urllib3-0:1.25.7-6.el7
Fixed · RHSA-2020:4299
CloudForms Management Engine 5
python-psutil
Will not fix
Red Hat Enterprise Linux 9
python-psutil
Not affected
Red Hat Enterprise Linux 9
python39:3.9/python-psutil
Not affected
Red Hat OpenStack Platform 10 (Newton)
python-psutil
Will not fix
Red Hat OpenStack Platform 13 (Queens)
python-psutil
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
python-psutil
Will not fix
Red Hat OpenStack Platform 15 (Stein)
python-psutil
Will not fix
Red Hat OpenStack Platform 16.1
python-psutil
Will not fix
Red Hat Quay 3
python-psutil
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Tower 3.6 for RHEL 7 | ansible-tower-36/ansible-runner-rhel7:1.4.4-2 | Fixed | RHSA-2020:4255 |
| Red Hat Ansible Tower 3.7 for RHEL 7 | ansible-tower-37/ansible-runner-rhel7:1.4.6-2 | Fixed | RHSA-2020:4254 |
| Red Hat Ansible Tower 3.7 for RHEL 7 | ansible-tower-37/ansible-tower-rhel7:3.7.4-1 | Fixed | RHSA-2020:5249 |
| Red Hat Enterprise Linux 8 | python-psutil-0:5.4.3-11.el8 | Fixed | RHSA-2021:4324 |
| Red Hat Enterprise Linux 8 | python38-devel:3.8-8050020210811101222.e3d35cca | Fixed | RHSA-2021:4162 |
| Red Hat Enterprise Linux 8 | python38:3.8-8050020210811101222.e3d35cca | Fixed | RHSA-2021:4162 |
| Red Hat OpenShift Container Platform 4.2 | python-psutil-0:5.6.6-1.el7ar | Fixed | RHSA-2020:2593 |
| Red Hat OpenShift Container Platform 4.3 | python-psutil-0:5.6.6-1.el7ar | Fixed | RHSA-2020:2635 |
| Red Hat OpenShift Container Platform 4.4 | python-psutil-0:5.6.6-1.el7ar | Fixed | RHSA-2020:2583 |
| Red Hat Satellite 6.9 for RHEL 7 | python-psutil-0:5.7.2-2.el7sat | Fixed | RHSA-2021:1313 |
| Red Hat Satellite 6.9 for RHEL 7 | python-psutil-0:5.7.2-2.el7sat | Fixed | RHSA-2021:1313 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-0:3.8.6-1.el7 | Fixed | RHSA-2020:4299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-psutil-0:5.6.4-5.el7 | Fixed | RHSA-2020:4299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-urllib3-0:1.25.7-6.el7 | Fixed | RHSA-2020:4299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-python38-python-0:3.8.6-1.el7 | Fixed | RHSA-2020:4299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-python38-python-psutil-0:5.6.4-5.el7 | Fixed | RHSA-2020:4299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-python38-python-urllib3-0:1.25.7-6.el7 | Fixed | RHSA-2020:4299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python38-python-0:3.8.6-1.el7 | Fixed | RHSA-2020:4299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python38-python-psutil-0:5.6.4-5.el7 | Fixed | RHSA-2020:4299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python38-python-urllib3-0:1.25.7-6.el7 | Fixed | RHSA-2020:4299 |
| CloudForms Management Engine 5 | python-psutil | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | python-psutil | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python39:3.9/python-psutil | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-psutil | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-psutil | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | python-psutil | Will not fix | n/a |
| Red Hat OpenStack Platform 15 (Stein) | python-psutil | Will not fix | n/a |
| Red Hat OpenStack Platform 16.1 | python-psutil | Will not fix | n/a |
| Red Hat Quay 3 | python-psutil | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (16)
- https://access.redhat.com/security/cve/CVE-2019-18874 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1772014 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0104 Advisory
- https://github.com/advisories/GHSA-qfc5-mcwq-26q8 Advisory
- https://github.com/giampaolo/psutil/blob/master/HISTORY.rst#566
- https://github.com/giampaolo/psutil/commit/7d512c8e4442a896d56505be3e78f1156f443465
- https://github.com/giampaolo/psutil/pull/1616 x_refsource_MISCThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/psutil/PYSEC-2019-41.yaml
- https://lists.debian.org/debian-lts-announce/2019/11/msg00018.html mailing-listx_refsource_MLIST
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2P7QI7MOTZTFXQYU23CP3RAWXCERMOAS/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OLETTJYZL2SMBUI4Q2NGBMGPDPP54SRG/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2P7QI7MOTZTFXQYU23CP3RAWXCERMOAS
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OLETTJYZL2SMBUI4Q2NGBMGPDPP54SRG
- https://nvd.nist.gov/vuln/detail/CVE-2019-18874
- https://usn.ubuntu.com/4204-1 vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-18874
Change history (0)
No recorded changes yet.