High severity7.4NVD Advisory· Published Jun 17, 2024· Updated Apr 15, 2026
CVE-2024-0397
CVE-2024-0397
Description
A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.
Patches
6bce693111bff542f3272f56fb228655c227b01c37f1d071429c97287d20537324b421b72Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
12- www.openwall.com/lists/oss-security/2024/06/17/2nvd
- github.com/python/cpython/commit/01c37f1d0714f5822d34063ca7180b595abf589dnvd
- github.com/python/cpython/commit/29c97287d205bf2f410f4895ebce3f43b5160524nvd
- github.com/python/cpython/commit/37324b421b72b7bc9934e27aba85d48d4773002envd
- github.com/python/cpython/commit/542f3272f56f31ed04e74c40635a913fbc12d286nvd
- github.com/python/cpython/commit/b228655c227b2ca298a8ffac44d14ce3d22f6faanvd
- github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766abnvd
- github.com/python/cpython/issues/114572nvd
- github.com/python/cpython/pull/114573nvd
- lists.debian.org/debian-lts-announce/2024/12/msg00000.htmlnvd
- mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/nvd
- security.netapp.com/advisory/ntap-20250411-0006/nvd
News mentions
0No linked articles in our index yet.