CVE-2022-48560 is a high-severity use-after-free vulnerability affecting Python through version 3.9, specifically within the heappushpop function of the heapq module, impacting Debian Linux and Python distributions. With a CVSS score of 7.5, it can be exploited remotely without user interaction, leading to a denial of service. While no public exploits, Metasploit modules, or Nuclei templates are available, and there's minimal community discussion or media coverage, organizations should still patch affected systems to mitigate the risk of potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.11CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.7.0, < 3.7.7CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.8.0, < 3.8.2CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
3.9.0CPE matchmatch criteria | cpe:2.3:a:python:python:3.9.0:alpha1:*:*:*:*:*:* | ||
3.9.0CPE matchmatch criteria | cpe:2.3:a:python:python:3.9.0:alpha2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.