Bug 2276518 (CVE-2023-6597)

Summary: CVE-2023-6597 python: Path traversal on tempfile.TemporaryDirectory
Product: [Other] Security Response Reporter: Marco Benatto <mbenatto>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aarif, agarcial, aoconnor, aprice, asegurap, bdettelb, caswilli, dfreiber, doconnor, drow, fjansen, hkataria, jburrell, jmitchel, jsamir, jsherril, jtanner, kaycoth, kholdawa, kshier, kyoshida, lbalhar, mpierce, orabin, psegedy, romain.geissler, sidakwo, sthirugn, teagle, vkrizan, vkumar, xiaoxwan, zzhou
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the tempfile.TemporaryDirectory class in python3/cpython3. The class may dereference symbolic links during permission-related errors, resulting in users that run privileged programs being able to modify permissions of files referenced by the symbolic link.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2276519    

Comment 2 Lumír Balhar 2024-04-22 20:48:04 UTC
The fix is in these upstream releases: 3.12.1, 3.11.8, 3.10.14, 3.9.19 and 3.8.19

Comment 12 errata-xmlrpc 2024-05-23 16:17:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:3347 https://access.redhat.com/errata/RHSA-2024:3347

Comment 13 errata-xmlrpc 2024-05-28 13:02:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2024:3391 https://access.redhat.com/errata/RHSA-2024:3391

Comment 14 errata-xmlrpc 2024-05-29 13:20:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:3466 https://access.redhat.com/errata/RHSA-2024:3466

Comment 16 errata-xmlrpc 2024-06-24 04:45:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:4058 https://access.redhat.com/errata/RHSA-2024:4058

Comment 17 errata-xmlrpc 2024-06-25 05:20:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:4077 https://access.redhat.com/errata/RHSA-2024:4077

Comment 18 errata-xmlrpc 2024-06-25 05:39:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:4078 https://access.redhat.com/errata/RHSA-2024:4078

Comment 19 errata-xmlrpc 2024-06-27 14:05:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2024:4166 https://access.redhat.com/errata/RHSA-2024:4166

Comment 20 errata-xmlrpc 2024-07-08 11:40:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2024:4370 https://access.redhat.com/errata/RHSA-2024:4370

Comment 21 errata-xmlrpc 2024-07-09 08:48:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2024:4406 https://access.redhat.com/errata/RHSA-2024:4406

Comment 22 errata-xmlrpc 2024-07-10 13:20:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2024:4456 https://access.redhat.com/errata/RHSA-2024:4456

Comment 23 errata-xmlrpc 2024-07-25 10:41:30 UTC
This issue has been addressed in the following products:

  Service Interconnect 1.4 for RHEL 9

Via RHSA-2024:4865 https://access.redhat.com/errata/RHSA-2024:4865

Comment 24 errata-xmlrpc 2024-07-25 14:29:19 UTC
This issue has been addressed in the following products:

  Service Interconnect 1 for RHEL 9

Via RHSA-2024:4871 https://access.redhat.com/errata/RHSA-2024:4871

Comment 25 errata-xmlrpc 2024-07-29 07:01:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2024:4896 https://access.redhat.com/errata/RHSA-2024:4896

Comment 26 errata-xmlrpc 2024-08-19 06:49:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2024:5535 https://access.redhat.com/errata/RHSA-2024:5535

Comment 27 errata-xmlrpc 2024-08-21 11:29:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2024:5689 https://access.redhat.com/errata/RHSA-2024:5689

Comment 32 errata-xmlrpc 2025-01-22 03:22:41 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2025:0364 https://access.redhat.com/errata/RHSA-2025:0364

Comment 33 errata-xmlrpc 2025-01-29 00:56:24 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.16

Via RHSA-2025:0650 https://access.redhat.com/errata/RHSA-2025:0650

Comment 34 errata-xmlrpc 2025-01-29 19:07:02 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.15

Via RHSA-2025:0646 https://access.redhat.com/errata/RHSA-2025:0646

Comment 35 errata-xmlrpc 2025-02-06 00:45:55 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2025:0832 https://access.redhat.com/errata/RHSA-2025:0832

Comment 36 errata-xmlrpc 2025-02-11 11:31:26 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.17

Via RHSA-2025:1120 https://access.redhat.com/errata/RHSA-2025:1120

Comment 37 errata-xmlrpc 2025-02-13 02:27:58 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2025:1116 https://access.redhat.com/errata/RHSA-2025:1116

Comment 38 errata-xmlrpc 2025-03-18 02:17:24 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2025:2705 https://access.redhat.com/errata/RHSA-2025:2705