Groups not dropped before running subprocess when using empty 'extra_groups' parameter
Published Dec 8, 2023
6.1
MEDIUMCVSS 3.1
EPSS 1.34%
Description
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases.
When using the `extra_groups=` parameter with an empty list as a value (ie `extra_groups=[]`) the logic regressed to not call `setgroups(0, NULL)` before calling `exec()`, thus not dropping the original processes' groups before starting the new process. There is no issue when the parameter isn't used or when any value is used besides an empty list.
This issue only impacts CPython processes run with sufficient privilege to make the `setgroups` system call (typically `root`).
Affected products
-
- Version 0StatusaffectedConstraints<3.12.1
- Version 3.13.0a1StatusaffectedConstraints<3.13.0a3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Python Software Foundation | CPython | unaffected |
|
-
- Version 3.12.0StatusaffectedConstraints-
- Version 3.13.0StatusaffectedConstraints-
- Version
Red Hat Enterprise Linux 10
python3.12
Not affected
Red Hat Enterprise Linux 6
python
Not affected
Red Hat Enterprise Linux 7
python
Not affected
Red Hat Enterprise Linux 7
python3
Not affected
Red Hat Enterprise Linux 8
python27:2.7/python2
Not affected
Red Hat Enterprise Linux 8
python3
Not affected
Red Hat Enterprise Linux 8
python3.11
Not affected
Red Hat Enterprise Linux 8
python3.12
Not affected
Red Hat Enterprise Linux 8
python36:3.6/python36
Not affected
Red Hat Enterprise Linux 8
python39-devel:3.9/python39
Not affected
Red Hat Enterprise Linux 8
python39:3.9/python39
Not affected
Red Hat Enterprise Linux 9
python3.11
Not affected
Red Hat Enterprise Linux 9
python3.12
Not affected
Red Hat Enterprise Linux 9
python3.9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | python3.12 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python27:2.7/python2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3.11 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3.12 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python39-devel:3.9/python39 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python39:3.9/python39 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.11 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.12 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Python versions as distributed with Red Hat Enterprise Linux 6, 7, 8 and 9 are not vulnerable to this flaw, as it doesn't contain the affected code or it ships a version where the fix is already present.
References (10)
- https://access.redhat.com/security/cve/CVE-2023-6507 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2293948 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58738 Advisory
- https://github.com/python/cpython/commit/10e9bb13b8dcaa414645b9bd10718d8f7179e82b patch
- https://github.com/python/cpython/commit/85bbfa8a4bbdbb61a3a84fbd7cb29a4096ab8a06 patch
- https://github.com/python/cpython/commit/9fe7655c6ce0b8e9adc229daf681b6d30e6b1610 patch
- https://github.com/python/cpython/issues/112334 issue-trackingIssue TrackingPatch
- https://mail.python.org/archives/list/security-announce@python.org/thread/AUL7QFHBLILGISS7U63B47AYSSGJJQZD/ vendor-advisoryThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-6507
- https://www.cve.org/CVERecord?id=CVE-2023-6507
Change history (0)
No recorded changes yet.