CVE-2022-48560

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
22/08/2023
Last modified:
08/12/2023

Description

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.6.11 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.7.0 (including) 3.7.7 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.8.0 (including) 3.8.2 (excluding)
cpe:2.3:a:python:python:3.9.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.9.0:alpha2:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*