Back

MEDIUM

Groups not dropped before running subprocess when using empty 'extra_groups' parameter

Published Dec 8, 2023

Description

An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases.

When using the `extra_groups=` parameter with an empty list as a value (ie `extra_groups=[]`) the logic regressed to not call `setgroups(0, NULL)` before calling `exec()`, thus not dropping the original processes' groups before starting the new process. There is no issue when the parameter isn't used or when any value is used besides an empty list.

This issue only impacts CPython processes run with sufficient privilege to make the `setgroups` system call (typically `root`).

Affected products

Remediation

Red Hat statement

The Python versions as distributed with Red Hat Enterprise Linux 6, 7, 8 and 9 are not vulnerable to this flaw, as it doesn't contain the affected code or it ships a version where the fix is already present.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PSF
Published Dec 8, 2023
Updated Jul 31, 2026
Reserved Dec 4, 2023
CISA Vulnrichment
Updated Jan 31, 2024
NVD
Status Modified
Modified Jul 31, 2026
Red Hat
Severity Moderate
Public date Dec 8, 2023
ENISA EUVD
Assigner PSF
Published Dec 8, 2023
Updated Jul 31, 2026
Exploited since n/a
EUVD-2023-58738