CVE-2024-9979
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-9979 is a newly discovered vulnerability affecting PyO3. This issue involves a use-after-free condition that can potentially result in memory corruption or crashes. The root cause is an unsound borrowing issue from weak Python references, which allows the affected memory to be accessed even after it has been freed. Attackers could exploit this vulnerability by manipulating data in a way that triggers the use-after-free condition, leading to arbitrary code execution or other malicious activities. Users of PyO3 are advised to apply patches or upgrades as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.