Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-3177

42
FAUCET Score

CVE-2021-3177 is a critical buffer overflow vulnerability in Python 3.x through 3.9.1, specifically within the _ctypes module, affecting products like Debian, Fedora, NetApp, Oracle, and Python itself. This flaw, caused by unsafe use of sprintf, can lead to remote code execution if Python applications process untrusted floating-point numbers. With a CVSS score of 9.8 (Critical), it presents a low-complexity attack vector over the network, allowing for complete compromise of confidentiality, integrity, and availability. While there are no known active exploits, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.6.0, <= 3.6.12CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.7.0, <= 3.7.9CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.8.0, <= 3.8.7CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.9.0, <= 3.9.1CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
18.85%
Probability of exploitation in next 30 days
EPSS Percentile
97.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1885 is in the 93rd percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (77)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 14141-12137Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14142-12137Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14143-12137Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14144-12137Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14145-12137Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14146-12137Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14147-12137Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14148-12137Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14149-12137Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14150-12137Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14151-12138Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14152-12138Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14153-12138Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14154-12138Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14155-12138Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14156-12138Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14147-12138Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14148-12138Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14157-12138Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: 14158-12138Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-3.7.9-4.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-libs-3.7.9-4.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-xml-3.7.9-4.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-curses-3.7.9-4.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-devel-3.7.9-4.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-tools-3.7.9-4.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-pip-3.7.9-4.cm1.noarch.rpm on CBL Mariner 1.0 x64Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-setuptools-3.7.9-4.cm1.noarch.rpm on CBL Mariner 1.0 x64Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-test-3.7.9-4.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-debuginfo-3.7.9-4.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-3.7.9-4.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-libs-3.7.9-4.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-xml-3.7.9-4.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-curses-3.7.9-4.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-devel-3.7.9-4.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-tools-3.7.9-4.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-pip-3.7.9-4.cm1.noarch.rpm on CBL Mariner 1.0 ARMFixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-setuptools-3.7.9-4.cm1.noarch.rpm on CBL Mariner 1.0 ARMFixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-test-3.7.9-4.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 3.7.9-4
microsoftpatch availablevia msrc
Product: python3-debuginfo-3.7.9-4.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 3.7.9-4
nodejspatch availablevia llm_extracted
View patch
oraclepatch availablevia nvd_reference
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-jinja2-0:2.10.3-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-lxml-0:4.4.1-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-pip-0:19.3.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-urllib3-0:1.25.7-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: python27-python-pygments-0:1.5-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-0:3.8.11-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-cryptography-0:2.8-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-lxml-0:4.4.1-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-pip-0:19.3.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-urllib3-0:1.25.7-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: python27-babel-0:0.9.6-10.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: python27-python-0:2.7.18-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: python27-python-jinja2-0:2.6-16.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-babel-0:2.7.0-12.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python-0:2.7.5-92.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3-0:3.6.8-37.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python27:2.7-8040020210122160212.cdb2db54
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python38:3.8-8040020210128125034.b1b639b6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: python27-babel-0:0.9.6-10.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: python27-python-0:2.7.18-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: python27-python-jinja2-0:2.6-16.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: python27-python-pygments-0:1.5-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-babel-0:2.7.0-12.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-0:3.8.11-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-cryptography-0:2.8-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-jinja2-0:2.10.3-6.el7
View patch
capnprotovendor investigatingvia llm_extracted
gcpvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
kongvendor investigatingvia llm_extracted
openwrtvendor investigatingvia llm_extracted
proxmoxvendor investigatingvia llm_extracted
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python2.7

Vendor Advisories (10)

nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
openwrtllm-openwrt-653330e88153242eCRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
gcpllm-gcp-0e8476cc66fb0775CRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
kongllm-kong-1666611432118a5eCRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
hanwhallm-hanwha-1994c6c2f0952354CRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
proxmoxllm-proxmox-2b2d17b42c53df6eCRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
capnprotollm-capnproto-2b74c0c7a557e2e2CRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
redhatCVE-2021-3177Moderate

python: Stack-based buffer overflow in PyCArg_repr in _ctypes/callproc.c

Jan 19, 2021
microsoft2021-Jan/CVE-2021-3177

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.

Jan 12, 2021

References

bugs.python.org / issue42938
ExploitIssue TrackingPatchVendor Advisory
github.com / python/cpython/pull/24239
PatchThird Party Advisory
lists.apache.org / thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
lists.debian.org / debian-lts-announce/2021/04/msg00005.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2022/02/msg00013.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2023/05/msg00024.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO
news.ycombinator.com / item
Third Party Advisory
python-security.readthedocs.io / vuln/ctypes-buffer-overflow-pycarg_repr.html
PatchThird Party Advisory
security.gentoo.org / glsa/202101-18
Third Party Advisory
security.netapp.com / advisory/ntap-20210226-0003
Third Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory