vulnerability
Amazon Linux 2023: CVE-2024-12254: Important priority package update for python3.12
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | Dec 6, 2024 | Feb 17, 2025 | Jul 9, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Dec 6, 2024
Added
Feb 17, 2025
Modified
Jul 9, 2025
Description
Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()
method would not "pause" writing and signal to the Protocol to drain
the buffer to the wire once the write buffer reached the "high-water
mark". Because of this, Protocols would not periodically drain the write
buffer potentially leading to memory exhaustion.
This
vulnerability likely impacts a small number of users, you must be using
Python 3.12.0 or later, on macOS or Linux, using the asyncio module
with protocols, and using .writelines() method which had new
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of
these factors are true then your usage of Python is unaffected.
method would not "pause" writing and signal to the Protocol to drain
the buffer to the wire once the write buffer reached the "high-water
mark". Because of this, Protocols would not periodically drain the write
buffer potentially leading to memory exhaustion.
This
vulnerability likely impacts a small number of users, you must be using
Python 3.12.0 or later, on macOS or Linux, using the asyncio module
with protocols, and using .writelines() method which had new
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of
these factors are true then your usage of Python is unaffected.
Solutions
amazon-linux-2023-upgrade-python3-12amazon-linux-2023-upgrade-python3-12-debugamazon-linux-2023-upgrade-python3-12-debuginfoamazon-linux-2023-upgrade-python3-12-debugsourceamazon-linux-2023-upgrade-python3-12-develamazon-linux-2023-upgrade-python3-12-idleamazon-linux-2023-upgrade-python3-12-libsamazon-linux-2023-upgrade-python3-12-testamazon-linux-2023-upgrade-python3-12-tkinter
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.