race condition with the ssl.SSLContext methods “cert_store_stats()” and
“get_ca_certs()”. The race condition can be triggered if the methods are
called at the same time as certificates are loaded into the SSLContext,
such as during the TLS handshake with a certificate directory configured.
This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3980-1 | python3.9 security update |
Debian DSA |
DSA-5759-1 | python3.11 security update |
EUVD |
EUVD-2024-16193 | A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5. |
Ubuntu USN |
USN-6928-1 | Python vulnerabilities |
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 06 Jun 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/a:redhat:enterprise_linux:9 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
Fri, 11 Apr 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 17 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python Software Foundation
Python Software Foundation cpython |
|
| CPEs | cpe:2.3:a:python_software_foundation:cpython:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Python Software Foundation
Python Software Foundation cpython |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2025-11-03T21:50:55.091Z
Reserved: 2024-01-10T14:05:31.635Z
Link: CVE-2024-0397
Updated: 2025-11-03T21:50:55.091Z
Status : Deferred
Published: 2024-06-17T16:15:10.217
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-0397
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN