CVE Vulnerabilities

CVE-2026-19445

Use After Free

Published: Sep 30, 2026 | Modified: Oct 03, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.

Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected.

Weakness

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory “belongs” to the code that operates on the new pointer.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatpython3.14-0:3.14.8-1.el10_2*
Red Hat Enterprise Linux 10RedHatpython3.12-0:3.12.15-1.el10_2*
Red Hat Enterprise Linux 8RedHatpython3.12-0:3.12.15-2.el8_10*
Red Hat Enterprise Linux 9RedHatpython3.12-0:3.12.15-1.el9_8*
Red Hat Enterprise Linux 9RedHatpython3.14-0:3.14.8-1.el9_8*
Red Hat Hardened ImagesRedHatpython3-15-main-3.15.0~rc2-1.1.hum1*

Potential Mitigations

References