← Back to CVE List

CVE-2024-0397

Published: 2024-06-17T16:15Z
Last Modified: 2025-04-11T22:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt