cbcvebase.
CVE-2022-42919
published 2022-11-07

CVE-2022-42919: Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing…

PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.63%
45.9th percentile
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from any user in the same machine local network namespace, which in many system configurations means any user on the same machine. Pickles can execute arbitrary code. Thus, this allows for local user privilege escalation to the user that any forkserver process is running as. Setting multiprocessing.util.abstract_sockets_supported to False is a workaround. The forkserver start method for multiprocessing is not the default start method. This issue is Linux specific because only Linux supports abstract namespace sockets. CPython before 3.9 does not make use of Linux abstract namespace sockets by default. Support for users manually specifying an abstract namespace socket was added as a bugfix in 3.7.8 and 3.8.3, but users would need to make specific uncommon API calls in order to do that in CPython before 3.9.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianpypy3< pypy3 7.3.11+dfsg-1 (bookworm)pypy3 7.3.11+dfsg-1 (bookworm)
debianpython2.7< pypy3 7.3.11+dfsg-1 (bookworm)pypy3 7.3.11+dfsg-1 (bookworm)
debianpython3.11< pypy3 7.3.11+dfsg-1 (bookworm)pypy3 7.3.11+dfsg-1 (bookworm)
debianpython3.9< pypy3 7.3.11+dfsg-1 (bookworm)pypy3 7.3.11+dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_python3_3.9.19-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_python3_3.7.16-1_on_cbl_mariner_1.0
pythonpython>= 3.10.0 < 3.10.93.10.9
pythonpython3.7.3 – 3.7.15
pythonpython3.8.3 – 3.8.15
pythonpython>= 3.9.0 < 3.9.163.9.16

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.