CVE-2022-42919 — Deserialization of Untrusted Data in Python
CWE-502 — Deserialization of Untrusted DataCWE-269 — Improper Privilege Management12 documents8 sources
Severity
7.8HIGHNVD
OSV7.6
EPSS
0.0%
top 88.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 7
Latest updateJul 11
Description
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from any user in the same machine local network namespace, which in many system configurations means any user on the same machine. Pickles can execute arbitrary code. Thus, this allows for local user privilege escalation to the user that any forkserv…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages11 packages
Also affects: Fedora 35, 36, 37
🔴Vulnerability Details
4📋Vendor Advisories
7Microsoft▶
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library when used with the forkserver start me↗2022-11-08