cbcvebase.
CVE-2023-6507
published 2023-12-08

CVE-2023-6507: An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases…

PriorityP426medium4.9CVSS 3.1
AVNACLPRHUINSUCNIHAN
EPSS
1.33%
67.8th percentile
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. When using the `extra_groups=` parameter with an empty list as a value (ie `extra_groups=[]`) the logic regressed to not call `setgroups(0, NULL)` before calling `exec()`, thus not dropping the original processes' groups before starting the new process. There is no issue when the parameter isn't used or when any value is used besides an empty list. This issue only impacts CPython processes run with sufficient privilege to make the `setgroups` system call (typically `root`).

Affected

11 ranges
VendorProductVersion rangeFixed in
debianpython2.7
debianpython3.11
debianpython3.9
msrcazl3_python3_3.12.0-4_on_azure_linux_3.0
msrcazl3_python3_3.12.3-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
pythonpython
pythonpython
python_software_foundationcpython>= 3.12.0 < 3.12.13.12.1
python_software_foundationcpython>= 3.13.0a1 < 3.13.0a33.13.0a3

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian6.1LOW
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_oracle4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.