A defect was discovered in the Python “ssl” module where there is a memory
race condition with the ssl.SSLContext methods “cert_store_stats()” and
“get_ca_certs()”. The race condition can be triggered if the methods are
called at the same time as certificates are loaded into the SSLContext,
such as during the TLS handshake with a certificate directory configured.
This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

Project Subscriptions

Vendors Products
Python Software Foundation Subscribe
Cpython Subscribe
Enterprise Linux Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3980-1 python3.9 security update
Debian DSA Debian DSA DSA-5759-1 python3.11 security update
EUVD EUVD EUVD-2024-16193 A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.
Ubuntu USN Ubuntu USN USN-6928-1 Python vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 03 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
References

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00393}

epss

{'score': 0.00401}


Fri, 06 Jun 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux

Fri, 11 Apr 2025 22:45:00 +0000

Type Values Removed Values Added
References

Tue, 17 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Python Software Foundation
Python Software Foundation cpython
CPEs cpe:2.3:a:python_software_foundation:cpython:*:*:*:*:*:*:*:*
Vendors & Products Python Software Foundation
Python Software Foundation cpython
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: PSF

Published:

Updated: 2025-11-03T21:50:55.091Z

Reserved: 2024-01-10T14:05:31.635Z

Link: CVE-2024-0397

cve-icon Vulnrichment

Updated: 2025-11-03T21:50:55.091Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-17T16:15:10.217

Modified: 2025-11-03T22:16:33.913

Link: CVE-2024-0397

cve-icon Redhat

Severity : Low

Publid Date: 2024-06-17T00:00:00Z

Links: CVE-2024-0397 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses