Double Free in psutil - CVE-2019-18874
Published: November 19, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists because of refcount mishandling within a "while" or "for" loop that converts system data into a Python object. A remote attacker can trigger double free error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
py-psutil (Alpine package)
python-psutil (Ubuntu package)
py3-psutil (Alpine package)
python38-wcwidth
python38-PyMySQL
python38-pluggy
python38-Cython
python38-wheel
python38-wheel-wheel
python38-markupsafe
python38-asn1crypto
python38-atomicwrites
python38-scipy
python38-pysocks
python38-py
python38-six
python38-cffi
python38-numpy-doc
python38-numpy-f2py
python38-numpy
python38-urllib3
python38-pyparsing
python38-babel
python38-cryptography
python38-psycopg2
python38-psycopg2-doc
python38-psycopg2-tests
python38-idna
python38-jinja2
python38-pycparser
python38-requests
python38-chardet
python38-debug
python38-rpm-macros
python38-tkinter
python38-test
python38
python38-libs
python38-idle
python38-devel
python38-ply
python38-lxml
python38-pytest
python38-mod_wsgi
python38-pyyaml
python-psutil
python-psutil-debuginfo
python-psutil-debugsource
python3-psutil
python2-psutil
python-psutil (Red Hat package)
python38-psutil
python38-more-itertools
python38-packaging
python38-attrs
python38-pip
python38-pip-wheel
python38-setuptools-wheel
python38-setuptools
python38-pytz
Ansible Automation Platform
Fedora
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
openEuler
PowerStore T
Red Hat OpenShift Container Platform
How to mitigate CVE-2019-18874
Ansible Automation Platform - addressed in versions 1.0, 1.1
python-psutil (Ubuntu package) - addressed in versions 3.4.2-1ubuntu0.1, 5.4.2-1ubuntu0.1, 5.5.1-1ubuntu0.19.04.1, 5.5.1-1ubuntu0.19.10.1
py3-psutil (Alpine package) - update to 5.6.7-r0
python38-wcwidth - update to 0.1.7-16
python38-PyMySQL - update to 0.10.1-1
python38-pluggy - update to 0.13.0-3
python38-Cython - update to 0.29.14-4
python38-wheel - update to 0.33.6-6
python38-wheel-wheel - update to 0.33.6-6
python38-markupsafe - update to 1.1.1-6
python38-asn1crypto - update to 1.2.0-3
python38-atomicwrites - update to 1.3.0-8
python38-scipy - update to 1.3.1-4
python38-pysocks - update to 1.7.1-4
python38-py - update to 1.8.0-8
python38-six - update to 1.12.0-10
python38-cffi - update to 1.13.2-3
python38-numpy-doc - update to 1.17.3-6
python38-numpy-f2py - update to 1.17.3-6
python38-numpy - update to 1.17.3-6
python38-urllib3 - update to 1.25.7-5
python38-pyparsing - update to 2.4.5-3
python38-babel - update to 2.7.0-11
python38-cryptography - update to 2.8-3
python38-psycopg2 - update to 2.8.4-4
python38-psycopg2-doc - update to 2.8.4-4
python38-psycopg2-tests - update to 2.8.4-4
python38-idna - update to 2.8-6
python38-jinja2 - update to 2.10.3-5
python38-pycparser - update to 2.19-3
python38-requests - update to 2.22.0-9
python38-chardet - update to 3.0.4-19
PowerStore T - update to 3.5.0.1-2083289
python38-debug - update to 3.8.12-1.0.1
python38-rpm-macros - update to 3.8.12-1.0.1
python38-tkinter - update to 3.8.12-1.0.1
python38-test - update to 3.8.12-1.0.1
python38 - update to 3.8.12-1.0.1
python38-libs - update to 3.8.12-1.0.1
python38-idle - update to 3.8.12-1.0.1
python38-devel - update to 3.8.12-1.0.1
python38-ply - update to 3.11-10
python38-lxml - update to 4.4.1-7
python38-pytest - update to 4.6.6-3
python38-mod_wsgi - update to 4.6.8-3
Red Hat OpenShift Container Platform - update to 4.11.0
python38-pyyaml - update to 5.4.1-1
python-psutil - update to 5.4.3-9
python-psutil-debuginfo - update to 5.4.3-9
python-psutil-debugsource - update to 5.4.3-9
python3-psutil - update to 5.4.3-9
python2-psutil - update to 5.4.3-9
python-psutil (Red Hat package) - addressed in versions 5.4.3-11.el8, 5.6.6-1.el7ar
python38-psutil - update to 5.6.4-4
python-psutil - addressed in versions 5.6.7-1.el7, 5.6.7-1.fc30, 5.6.7-1.fc31
python38-more-itertools - update to 7.2.0-5
python38-packaging - update to 19.2-3
python38-attrs - update to 19.3.0-3
python38-pip - update to 19.3.1-5
python38-pip-wheel - update to 19.3.1-5
python38-setuptools-wheel - update to 41.6.0-5
python38-setuptools - update to 41.6.0-5
python38-pytz - update to 2019.3-3
External References
Related Security Bulletins
- Remote code execution in psutil module for Python
- Ubuntu update for psutil
- Double Free in py-psutil (Alpine package)
- Double Free in py3-psutil (Alpine package)
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Red Hat OpenShift Container Platform 4.3 update for python-psutil
- Red Hat OpenShift Container Platform 4.4 update for python-psutil
- Red Hat OpenShift Container Platform 4.2 update for python-psutil
- Red Hat Enterprise Linux 8 update for python-psutil
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- openEuler update for python-psutil
- Red Hat Enterprise Linux 8 update for the python38:3.8 and python38-devel:3.8 modules
- Anolis OS update for python38:3.8 module
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages
- Fedora 30 update for python-psutil
- Fedora 31 update for python-psutil
- Fedora EPEL 7 update for python-psutil