Medium severity6.1NVD Advisory· Published Dec 8, 2023· Updated Jul 31, 2026
CVE-2023-6507
CVE-2023-6507
Description
An issue was found in CPython 3.12.0 subprocess module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases.
When using the extra_groups= parameter with an empty list as a value (ie extra_groups=[]) the logic regressed to not call setgroups(0, NULL) before calling exec(), thus not dropping the original processes' groups before starting the new process. There is no issue when the parameter isn't used or when any value is used besides an empty list.
This issue only impacts CPython processes run with sufficient privilege to make the setgroups system call (typically root).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:python:python:3.12.0:-:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:python:python:3.12.0:-:*:*:*:*:*:*
- cpe:2.3:a:python:python:3.13.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:python:python:3.13.0:alpha2:*:*:*:*:*:*
- (no CPE)range: <3.12.1
- (no CPE)range: 3.12.0
- osv-coords4 versionspkg:bitnami/libpythonpkg:bitnami/pythonpkg:bitnami/python-minpkg:rpm/opensuse/python312&distro=openSUSE%20Tumbleweed
>= 3.12.0, < 3.12.1+ 3 more
- (no CPE)range: >= 3.12.0, < 3.12.1
- (no CPE)range: >= 3.12.0, < 3.12.1
- (no CPE)range: >= 3.12.0, < 3.12.1
- (no CPE)range: < 3.12.1-1.1
Patches
Vulnerability mechanics
References
5- github.com/python/cpython/issues/112334nvdIssue TrackingPatch
- mail.python.org/archives/list/[email protected]/thread/AUL7QFHBLILGISS7U63B47AYSSGJJQZD/nvdThird Party Advisory
- github.com/python/cpython/commit/10e9bb13b8dcaa414645b9bd10718d8f7179e82bnvd
- github.com/python/cpython/commit/85bbfa8a4bbdbb61a3a84fbd7cb29a4096ab8a06nvd
- github.com/python/cpython/commit/9fe7655c6ce0b8e9adc229daf681b6d30e6b1610nvd
News mentions
0No linked articles in our index yet.