Skip to content

[CVE-2022-37454] Buffer overflow in the _sha3 module in python versions <= 3.10 #98517

Closed
@botovq

Description

@botovq

CVE-2022-37454 affects Python versions prior to 3.11. The fix discussed in XKCP's advisory can be adapted to these versions. The discoverer's writeup contains code that might be turned into regression tests.

Python 3.11 and later switched to using tiny_sha3 in GH-32060, so they should not be affected.

Linked PRs

Metadata

Metadata

Labels

3.10only security fixes3.7 (EOL)end of life3.8 (EOL)end of life3.9only security fixestype-bugAn unexpected behavior, bug, or errortype-securityA security issue

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions