Use-After-Free Vulnerability in PyO3 Could Lead to Memory Corruption or Crashes
CVE-2024-9979
5.3MEDIUM
Key Information:
- Vendor
- CVE Published:
- 15 October 2024
What is CVE-2024-9979?
A flaw in PyO3 enables a use-after-free issue that can result in memory corruption or application crashes. This vulnerability stems from unsound borrowing from weak Python references, which could be exploited by attackers or inadvertently trigger instability in applications that rely on the affected library. Developers utilizing PyO3 should review their code for instances that may be influenced by this vulnerability and ensure they adopt the latest secure version to mitigate potential risks.
