A defect was discovered in the Python “ssl” module where there is a memory
race condition with the ssl.SSLContext methods “cert_store_stats()” and
“get_ca_certs()”. The race condition can be triggered if the methods are
called at the same time as certificates are loaded into the SSLContext,
such as during the TLS handshake with a certificate directory configured.
This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Fri, 06 Jun 2025 21:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Redhat Redhat enterprise Linux | |
| CPEs | cpe:/a:redhat:enterprise_linux:9 | |
| Vendors & Products | Redhat Redhat enterprise Linux | 
Fri, 11 Apr 2025 22:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Tue, 17 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Python Software Foundation Python Software Foundation cpython | |
| CPEs | cpe:2.3:a:python_software_foundation:cpython:*:*:*:*:*:*:*:* | |
| Vendors & Products | Python Software Foundation Python Software Foundation cpython | |
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: PSF
Published: 2024-06-17T15:09:40.896Z
Updated: 2025-04-11T22:03:13.624Z
Reserved: 2024-01-10T14:05:31.635Z
Link: CVE-2024-0397
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-04-11T22:03:13.624Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2024-06-17T16:15:10.217
Modified: 2025-04-11T22:15:28.650
Link: CVE-2024-0397
 Redhat
                        Redhat