CVE Vulnerabilities

CVE-2023-6597

Published: Mar 19, 2024 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was found in the CPython tempfile.TemporaryDirectory class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.

The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-62.el8_10*
Red Hat Enterprise Linux 8RedHatpython39:3.9-8100020240516111311.d47b87a4*
Red Hat Enterprise Linux 8RedHatpython39-devel:3.9-8100020240516111311.d47b87a4*
Red Hat Enterprise Linux 8RedHatpython3.11-0:3.11.9-1.el8_10*
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-62.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatpython3-0:3.6.8-24.el8_2.3*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatpython3-0:3.6.8-39.el8_4.5*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatpython3-0:3.6.8-39.el8_4.5*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatpython3-0:3.6.8-39.el8_4.5*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatpython3-0:3.6.8-47.el8_6.6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatpython3-0:3.6.8-47.el8_6.6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatpython3-0:3.6.8-47.el8_6.6*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatpython3-0:3.6.8-51.el8_8.6*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatpython3.11-0:3.11.2-2.el8_8.3*
Red Hat Enterprise Linux 9RedHatpython3.11-0:3.11.7-1.el9_4.1*
Red Hat Enterprise Linux 9RedHatpython3.9-0:3.9.18-3.el9_4.1*
Red Hat Enterprise Linux 9RedHatpython3.9-0:3.9.18-3.el9_4.1*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatpython3.9-0:3.9.10-4.el9_0.4*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatpython3.11-0:3.11.2-2.el9_2.4*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatpython3.9-0:3.9.16-1.el9_2.5*
Red Hat OpenShift Container Platform 4.12RedHatrhcos-412.86.202501011408-0*
Red Hat OpenShift Container Platform 4.13RedHatrhcos-413.92.202501201944-0*
Red Hat OpenShift Container Platform 4.14RedHatrhcos-414.92.202501150310-0*
Red Hat OpenShift Container Platform 4.15RedHatrhcos-415.92.202501152057-0*
Red Hat OpenShift Container Platform 4.16RedHatrhcos-416.94.202501220853-0*
Red Hat OpenShift Container Platform 4.17RedHatrhcos-417.94.202502051822-0*
Red Hat OpenShift Container Platform 4.18RedHatrhcos-418.94.202503102036-0*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-router-rhel9:2.4.3-5*
Service Interconnect 1 for RHEL 9RedHatservice-interconnect/skupper-router-rhel9:2.5.3-2*
Python3.10Ubuntujammy*
Python3.10Ubuntuupstream*
Python3.11Ubuntuesm-apps/jammy*
Python3.11Ubuntujammy*
Python3.11Ubuntumantic*
Python3.12Ubuntumantic*
Python3.4Ubuntutrusty/esm*
Python3.5Ubuntuesm-infra/xenial*
Python3.7Ubuntuesm-apps/bionic*
Python3.8Ubuntuesm-apps/bionic*
Python3.8Ubuntuesm-infra/focal*
Python3.8Ubuntufocal*
Python3.8Ubuntuupstream*
Python3.9Ubuntuesm-apps/focal*
Python3.9Ubuntufocal*
Python3.9Ubuntuupstream*

References