DEBIAN-CVE-2026-63349

Source
https://security-tracker.debian.org/tracker/CVE-2026-63349
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63349.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-63349
Upstream
Published
2026-09-18T17:16:59Z
Modified
2026-09-20T20:00:08Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_process() forwards the group argument to the backend instead of extra_groups. A caller that supplies extra_groups=[] to clear inherited supplementary groups can therefore launch a child that retains the parent process groups, undermining a privilege-dropping boundary. If group is also supplied, the integer group value is passed where an iterable of supplementary groups is expected and the launch can fail with TypeError. This issue affects POSIX applications that rely on AnyIO subprocess helpers to launch less-privileged child processes. This issue is fixed in version 4.14.2.

References

Affected packages

Debian:12 / python-anyio

Package

Name
python-anyio
Purl
pkg:deb/debian/python-anyio?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.2-1
3.7.0-1
4.*
4.1.0-1
4.2.0-1
4.3.0-1
4.4.0-1
4.6.0-1
4.6.2-1
4.6.2-2
4.6.2-3
4.6.2-4
4.7.0-1
4.8.0-1
4.8.0-2
4.8.0-3
4.11.0-1
4.11.0-2
4.11.0-3
4.12.1-1
4.12.1-2
4.12.1-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63349.json"

Debian:13 / python-anyio

Package

Name
python-anyio
Purl
pkg:deb/debian/python-anyio?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.8.0-3
4.11.0-1
4.11.0-2
4.11.0-3
4.12.1-1
4.12.1-2
4.12.1-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63349.json"

Debian:14 / python-anyio

Package

Name
python-anyio
Purl
pkg:deb/debian/python-anyio?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.8.0-3
4.11.0-1
4.11.0-2
4.11.0-3
4.12.1-1
4.12.1-2
4.12.1-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63349.json"