Regular-expression DoS when parsing TarFile headers
Published Sep 3, 2024
7.5
HIGHCVSS 3.1
EPSS 2.20%
Description
There is a MEDIUM severity vulnerability affecting CPython.
Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Affected products
-
- Version 0StatusaffectedConstraints<3.8.20
- Version 3.10.0StatusaffectedConstraints<3.10.15
- Version 3.11.0StatusaffectedConstraints<3.11.10
- Version 3.12.0StatusaffectedConstraints<3.12.6
- Version 3.13.0a1StatusaffectedConstraints<3.13.0rc2
- Version 3.9.0StatusaffectedConstraints<3.9.20
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Python Software Foundation | CPython | unaffected |
|
- < 3.8.20
- ≥ 3.9.0 · < 3.9.20
- ≥ 3.10.0 · < 3.10.15
- ≥ 3.11.0 · < 3.11.10
- ≥ 3.12.0 · < 3.12.6
- 3.13.0
- 3.13.0
- 3.13.0
- 3.13.0
- 3.13.0
- 3.13.0
- 3.13.0
- 3.13.0
- 3.13.0
- 3.13.0
- 3.13.0
- 3.13.0
-
- Version 0StatusaffectedConstraints<3.8.20
- Version 3.10.0StatusaffectedConstraints<3.10.15
- Version 3.11.0StatusaffectedConstraints<3.11.10
- Version 3.12.0StatusaffectedConstraints<3.12.6
- Version 3.13.0a1StatusaffectedConstraints<3.13.0rc2
- Version 3.9.0StatusaffectedConstraints<3.9.20
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Red Hat Enterprise Linux 10
python3.12-0:3.12.9-1.el10
Fixed · RHBA-2025:6294
Red Hat Enterprise Linux 7 Extended Lifecycle Support
python3-0:3.6.8-21.el7_9.1
Fixed · RHSA-2025:1750
Red Hat Enterprise Linux 7.7 Advanced Update Support
python3-0:3.6.8-10.el7_7.1
Fixed · RHSA-2024:8490
Red Hat Enterprise Linux 8
python3-0:3.6.8-67.el8_10
Fixed · RHSA-2024:6975
Red Hat Enterprise Linux 8
python3-0:3.6.8-67.el8_10
Fixed · RHSA-2024:6975
Red Hat Enterprise Linux 8
python3.11-0:3.11.10-1.el8_10
Fixed · RHSA-2024:8838
Red Hat Enterprise Linux 8
python3.12-0:3.12.6-1.el8_10
Fixed · RHSA-2024:8836
Red Hat Enterprise Linux 8
python39-devel:3.9-8100020240927003152.d47b87a4
Fixed · RHSA-2024:8359
Red Hat Enterprise Linux 8
python39:3.9-8100020240927003152.d47b87a4
Fixed · RHSA-2024:8359
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
python39:3.9-8040020241017072554.63cd9eba
Fixed · RHSA-2024:8977
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
python39:3.9-8040020241017072554.63cd9eba
Fixed · RHSA-2024:8977
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
python39:3.9-8040020241017072554.63cd9eba
Fixed · RHSA-2024:8977
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
python39:3.9-8060020241017081122.6a631399
Fixed · RHSA-2024:8797
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
python39:3.9-8060020241017081122.6a631399
Fixed · RHSA-2024:8797
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
python39:3.9-8060020241017081122.6a631399
Fixed · RHSA-2024:8797
Red Hat Enterprise Linux 8.8 Extended Update Support
python3.11-0:3.11.2-2.el8_8.4
Fixed · RHSA-2024:7647
Red Hat Enterprise Linux 8.8 Extended Update Support
python39:3.9-8080020241016061730.93c2fc2f
Fixed · RHSA-2024:8504
Red Hat Enterprise Linux 9
python3.11-0:3.11.7-1.el9_4.6
Fixed · RHSA-2024:8374
Red Hat Enterprise Linux 9
python3.11-0:3.11.9-7.el9_5.1
Fixed · RHSA-2024:9450
Red Hat Enterprise Linux 9
python3.12-0:3.12.1-4.el9_4.4
Fixed · RHSA-2024:8447
Red Hat Enterprise Linux 9
python3.12-0:3.12.5-2.el9_5.1
Fixed · RHSA-2024:9451
Red Hat Enterprise Linux 9
python3.9-0:3.9.18-3.el9_4.6
Fixed · RHSA-2024:8446
Red Hat Enterprise Linux 9
python3.9-0:3.9.18-3.el9_4.6
Fixed · RHSA-2024:8446
Red Hat Enterprise Linux 9
python3.9-0:3.9.19-8.el9_5.1
Fixed · RHSA-2024:9468
Red Hat Enterprise Linux 9
python3.9-0:3.9.19-8.el9_5.1
Fixed · RHSA-2024:9468
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
python3.9-0:3.9.10-4.el9_0.6
Fixed · RHSA-2024:8130
Red Hat Enterprise Linux 9.2 Extended Update Support
python3.11-0:3.11.2-2.el9_2.6
Fixed · RHSA-2024:7415
Red Hat Enterprise Linux 9.2 Extended Update Support
python3.9-0:3.9.16-1.el9_2.8
Fixed · RHSA-2024:6909
Red Hat Enterprise Linux 6
python
Out of support scope
Red Hat Enterprise Linux 7
python
Out of support scope
Red Hat Enterprise Linux 8
python36:3.6/python36
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/bootc-nvidia-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | python3.12-0:3.12.9-1.el10 | Fixed | RHBA-2025:6294 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | python3-0:3.6.8-21.el7_9.1 | Fixed | RHSA-2025:1750 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | python3-0:3.6.8-10.el7_7.1 | Fixed | RHSA-2024:8490 |
| Red Hat Enterprise Linux 8 | python3-0:3.6.8-67.el8_10 | Fixed | RHSA-2024:6975 |
| Red Hat Enterprise Linux 8 | python3-0:3.6.8-67.el8_10 | Fixed | RHSA-2024:6975 |
| Red Hat Enterprise Linux 8 | python3.11-0:3.11.10-1.el8_10 | Fixed | RHSA-2024:8838 |
| Red Hat Enterprise Linux 8 | python3.12-0:3.12.6-1.el8_10 | Fixed | RHSA-2024:8836 |
| Red Hat Enterprise Linux 8 | python39-devel:3.9-8100020240927003152.d47b87a4 | Fixed | RHSA-2024:8359 |
| Red Hat Enterprise Linux 8 | python39:3.9-8100020240927003152.d47b87a4 | Fixed | RHSA-2024:8359 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | python39:3.9-8040020241017072554.63cd9eba | Fixed | RHSA-2024:8977 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | python39:3.9-8040020241017072554.63cd9eba | Fixed | RHSA-2024:8977 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | python39:3.9-8040020241017072554.63cd9eba | Fixed | RHSA-2024:8977 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | python39:3.9-8060020241017081122.6a631399 | Fixed | RHSA-2024:8797 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | python39:3.9-8060020241017081122.6a631399 | Fixed | RHSA-2024:8797 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | python39:3.9-8060020241017081122.6a631399 | Fixed | RHSA-2024:8797 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | python3.11-0:3.11.2-2.el8_8.4 | Fixed | RHSA-2024:7647 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | python39:3.9-8080020241016061730.93c2fc2f | Fixed | RHSA-2024:8504 |
| Red Hat Enterprise Linux 9 | python3.11-0:3.11.7-1.el9_4.6 | Fixed | RHSA-2024:8374 |
| Red Hat Enterprise Linux 9 | python3.11-0:3.11.9-7.el9_5.1 | Fixed | RHSA-2024:9450 |
| Red Hat Enterprise Linux 9 | python3.12-0:3.12.1-4.el9_4.4 | Fixed | RHSA-2024:8447 |
| Red Hat Enterprise Linux 9 | python3.12-0:3.12.5-2.el9_5.1 | Fixed | RHSA-2024:9451 |
| Red Hat Enterprise Linux 9 | python3.9-0:3.9.18-3.el9_4.6 | Fixed | RHSA-2024:8446 |
| Red Hat Enterprise Linux 9 | python3.9-0:3.9.18-3.el9_4.6 | Fixed | RHSA-2024:8446 |
| Red Hat Enterprise Linux 9 | python3.9-0:3.9.19-8.el9_5.1 | Fixed | RHSA-2024:9468 |
| Red Hat Enterprise Linux 9 | python3.9-0:3.9.19-8.el9_5.1 | Fixed | RHSA-2024:9468 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | python3.9-0:3.9.10-4.el9_0.6 | Fixed | RHSA-2024:8130 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | python3.11-0:3.11.2-2.el9_2.6 | Fixed | RHSA-2024:7415 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | python3.9-0:3.9.16-1.el9_2.8 | Fixed | RHSA-2024:6909 |
| Red Hat Enterprise Linux 6 | python | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/bootc-nvidia-rhel9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is classified as moderate severity rather than important because while it does allow for a denial of service (DoS) attack via excessive backtracking in the tarfile module, it does not enable remote code execution or compromise the integrity or confidentiality of data. Exploitation requires an attacker to provide a specially crafted tar archive and relies on the victim's system processing that file, which limits the attack vector. Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (17)
- http://www.openwall.com/lists/oss-security/2024/09/03/5 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-6232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2309426 Issue Tracking
- https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4 patch
- https://github.com/python/cpython/commit/4eaf4891c12589e3c7bdad5f5b076e4c8392dd06 patch
- https://github.com/python/cpython/commit/743acbe872485dc18df4d8ab2dc7895187f062c4 patch
- https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64d patch
- https://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877 patch
- https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf patch
- https://github.com/python/cpython/commit/ed3a49ea734ada357ff4442996fd4ae71d253373 patch
- https://github.com/python/cpython/issues/121285 issue-trackingExploitIssue TrackingPatch
- https://github.com/python/cpython/pull/121286 patchIssue Tracking
- https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html
- https://mail.python.org/archives/list/security-announce@python.org/thread/JRYFTPRHZRTLMZLWQEUHZSJXNHM4ACTY/ vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6232
- https://security.netapp.com/advisory/ntap-20241018-0007/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6232
Change history (0)
No recorded changes yet.