CVE-2024-3219
The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local connected pair of sockets. The connection between the two sockets was not verified before passing the two sockets back to the user, which leaves the server socket vulnerable to a connection race from a malicious local peer. Platforms that support AF_UNIX such as Linux and macOS are not affected by this vulnerability. Versions prior to CPython 3.5 are not affected due to the vulnerable API not being included.
- CVSS 4.0
- 5.1 MEDIUM
- EPSS
- 0.2% (16th percentile)
- Weakness
- CWE-306
- NVD status
- Deferred
- Published
- 2024-07-29
No indexed exploits for CVE-2024-3219 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-3219 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.