Impact
This bug is a use‑after‑free flaw in CPython’s SSL handling: when a TLS client invokes the sni_callback and assigns a different SSLContext to an SSLSocket, the prior context can be deallocated while still referenced. A remote, unauthenticated client can then cause the server to crash or, if the freed pointer is abused, execute arbitrary code. The vulnerability is classified as CWE‑416 and scored 9.2 on the CVSS scale, indicating a critical severity.
Affected Systems
The flaw affects Python Software Foundation CPython servers that create a new SSLContext for each connection or replace the context while connections are active. Servers that wrap their listening socket with a single SSLContext are not affected. No specific version ranges are listed in the advisory, so any CPython instance employing sni_callback in the described manner is potentially vulnerable.
Risk and Exploitability
The high CVSS score and lack of mitigation from existing security controls mean this vulnerability poses an immediate threat. An attacker can exploit the flaw simply by establishing an unauthenticated TLS connection that triggers the sni_callback. The EPSS score is not available, and the vulnerability is not listed in KEV, but the potential for arbitrary code execution and denial of service makes it a likely target for malicious actors. Servers should be considered exposed until a patch that preserves the SSLContext is applied or the flaw is otherwise mitigated.
OpenCVE Enrichment