Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2022-48560
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-48560
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48560.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-48560
Aliases
BIT-libpython-2022-48560
BIT-python-2022-48560
BIT-python-min-2022-48560
GHSA-pvw5-cvp6-cv92
PSF-2023-11
Downstream
DEBIAN-CVE-2022-48560
DLA-3575-1
DLA-3614-1
RHSA-2024:0114
RHSA-2024:0430
RHSA-2024:0586
RHSA-2024:2987
RLSA-2024:2987
SUSE-SU-2024:1667-1
SUSE-SU-2024:1862-1
UBUNTU-CVE-2022-48560
USN-6394-1
USN-6394-2
USN-6891-1
USN-7180-1
openSUSE-SU-2024:13488-1
Related
ALSA-2024:0114
ALSA-2024:2987
CGA-grx3-mgr7-fqm5
CGA-jcfc-86xf-53qf
SUSE-SU-2024:1667-1
SUSE-SU-2024:1862-1
openSUSE-SU-2024:13488-1
Published
2023-08-22T19:16:31Z
Modified
2025-08-11T14:44:38.059693Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
[none]
Details
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
References
https://bugs.python.org/issue39421
https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html
https://security.netapp.com/advisory/ntap-20230929-0008/
https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZ5OOBWNYWXFTZDMCGHJVGDLDTHLWITJ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VO7Y2YZSDK3UYJD2KBGLXRTGNG6T326J/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZ5OOBWNYWXFTZDMCGHJVGDLDTHLWITJ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VO7Y2YZSDK3UYJD2KBGLXRTGNG6T326J/
Affected packages
Git
/
github.com/python/cpython
Affected ranges
Type
GIT
Repo
https://github.com/python/cpython
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
d56cd4006a1c5e07b0bf69fad9fc8e2fbf6aa855
CVE-2022-48560 - OSV