Resource exhaustion in Python - CVE-2020-14422
Published: July 7, 2020 / Updated: July 15, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application improperly computes hash values in the IPv4Interface and IPv6Interface classes within the Lib/ipaddress.py in Python. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created.
Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
CentOS
Red Hat Enterprise Linux Server
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64
Ubuntu
Opensuse
openEuler
Ansible Automation Platform
IBM Match 360
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
python3 (Red Hat package)
python3 (Alpine package)
python3.6 (Ubuntu package)
python3.11 (Ubuntu package)
python3.5-minimal (Ubuntu package)
python3.5 (Ubuntu package)
python3.11-minimal (Ubuntu package)
python3.7-minimal (Ubuntu package)
python3.7 (Ubuntu package)
python3.6-minimal (Ubuntu package)
python3.8 (Ubuntu package)
python3.8-minimal (Ubuntu package)
python3.9 (Ubuntu package)
python3.9-minimal (Ubuntu package)
python38-wcwidth
python38-PyMySQL
python38-pluggy
python38-Cython
python38-wheel
python38-wheel-wheel
python38-markupsafe
python38-asn1crypto
python38-atomicwrites
python38-scipy
python38-pysocks
python38-py
python38-six
python38-cffi
python38-numpy
python38-numpy-f2py
python38-numpy-doc
python38-urllib3
python38-pyparsing
python38-babel
python2.7 (Ubuntu package)
python2.7-minimal (Ubuntu package)
python38-cryptography
python38-psycopg2
python38-psycopg2-doc
python38-psycopg2-tests
python38-idna
python38-jinja2
python38-pycparser
python38-requests
python38-chardet
python3.4 (Ubuntu package)
python3.4-minimal (Ubuntu package)
python34
python35
python3.5
python36
python3
python37
mingw-python3
python38
python3-docs
python38-debug
python38-tkinter
python38-test
python38-libs
python38-idle
python38-rpm-macros
python38-devel
python39
python3.10 (Ubuntu package)
python3.10-minimal (Ubuntu package)
python38-ply
python3.12 (Ubuntu package)
python3.12-minimal (Ubuntu package)
python38-lxml
python38-pytest
python38-mod_wsgi
python38-pyyaml
python38-psutil
python38-more-itertools
python38-packaging
python38-attrs
python38-pip-wheel
python38-pip
python-pip-help
python-pip
python3-pip
python-pip-wheel
python2-pip
python38-setuptools-wheel
python38-setuptools
python38-pytz
RecoverPoint for Virtual Machines
Red Hat OpenShift Container Platform
How to mitigate CVE-2020-14422
Ansible Automation Platform - update to 1.2.4
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0
Quay - update to 3.3.3
python3 (Red Hat package) - addressed in versions 3.6.8-18.el7, 3.6.8-31.el8
python3 (Alpine package) - update to 3.6.9-r3
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
python3.6 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6.9-1~18.04ubuntu1.12
python3.11 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.5-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.5.2-2ubuntu0~16.04.11
python3.5 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 3.5.2-2ubuntu0~16.04.11
python3.11-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.7-minimal (Ubuntu package) - update to Ubuntu Pro
python3.7 (Ubuntu package) - update to Ubuntu Pro
python3.6-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6.9-1~18.04ubuntu1.12
python3.8 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.2-1ubuntu1.2, 3.8.10-0ubuntu1~20.04.10
python3.8-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.2-1ubuntu1.2, 3.8.10-0ubuntu1~20.04.10
python3.9 (Ubuntu package) - update to Ubuntu Pro
python3.9-minimal (Ubuntu package) - update to Ubuntu Pro
python38-wcwidth - update to 0.1.7-16
python38-PyMySQL - update to 0.10.1-1
python38-pluggy - update to 0.13.0-3
python38-Cython - update to 0.29.14-4
python38-wheel - update to 0.33.6-6
python38-wheel-wheel - update to 0.33.6-6
python38-markupsafe - update to 1.1.1-6
python38-asn1crypto - update to 1.2.0-3
python38-atomicwrites - update to 1.3.0-8
python38-scipy - update to 1.3.1-4
python38-pysocks - update to 1.7.1-4
python38-py - update to 1.8.0-8
python38-six - update to 1.12.0-10
python38-cffi - update to 1.13.2-3
python38-numpy - update to 1.17.3-6
python38-numpy-f2py - update to 1.17.3-6
python38-numpy-doc - update to 1.17.3-6
python38-urllib3 - update to 1.25.7-5
python38-pyparsing - update to 2.4.5-3
python38-babel - update to 2.7.0-11
python2.7 (Ubuntu package) - addressed in versions 2.7.3-0ubuntu3.18, 2.7.6-8ubuntu0.6+esm6, 2.7.12-1ubuntu0~16.04.12, 2.7.17-1~18.04ubuntu1.11
python2.7-minimal (Ubuntu package) - addressed in versions 2.7.3-0ubuntu3.18, 2.7.6-8ubuntu0.6+esm6, 2.7.12-1ubuntu0~16.04.12, 2.7.17-1~18.04ubuntu1.11
python38-cryptography - update to 2.8-3
python38-psycopg2 - update to 2.8.4-4
python38-psycopg2-doc - update to 2.8.4-4
python38-psycopg2-tests - update to 2.8.4-4
python38-idna - update to 2.8-6
python38-jinja2 - update to 2.10.3-5
python38-pycparser - update to 2.19-3
python38-requests - update to 2.22.0-9
python38-chardet - update to 3.0.4-19
python3.4 (Ubuntu package) - update to 3.4.3-1ubuntu1~14.04.7+esm7
python3.4-minimal (Ubuntu package) - update to 3.4.3-1ubuntu1~14.04.7+esm7
python34 - addressed in versions 3.4.10-6.el7, 3.4.10-11.fc32
python35 - addressed in versions 3.5.9-9.fc31, 3.5.9-9.fc32
python3.5 - addressed in versions 3.5.9-9.fc33, 3.5.9-9.fc34
python36 - addressed in versions 3.6.11-3.fc31, 3.6.11-3.fc32
python3 - addressed in versions 3.7.8-2.fc31, 3.8.4-1.fc32, 3.8.5-1.fc32
python37 - update to 3.7.8-2.fc32
mingw-python3 - addressed in versions 3.8.3-2.fc32, 3.8.3-3.fc32
python38 - addressed in versions 3.8.4-1.fc31, 3.8.5-1.fc31
python3-docs - addressed in versions 3.8.4-1.fc32, 3.8.5-1.fc32
python38-debug - update to 3.8.12-1.0.1
python38-tkinter - update to 3.8.12-1.0.1
python38-test - update to 3.8.12-1.0.1
python38-libs - update to 3.8.12-1.0.1
python38-idle - update to 3.8.12-1.0.1
python38-rpm-macros - update to 3.8.12-1.0.1
python38-devel - update to 3.8.12-1.0.1
python38 - update to 3.8.12-1.0.1
python39 - addressed in versions 3.9.0~b4-1.fc31, 3.9.0~b4-1.fc32
python3.10 (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.10-minimal (Ubuntu package) - update to 3.10.12-1~22.04.4
python38-ply - update to 3.11-10
python3.12 (Ubuntu package) - update to 3.12.0-1ubuntu0.1
python3.12-minimal (Ubuntu package) - update to 3.12.0-1ubuntu0.1
python38-lxml - update to 4.4.1-7
Red Hat OpenShift Container Platform - update to 4.5.20
python38-pytest - update to 4.6.6-3
python38-mod_wsgi - update to 4.6.8-3
IBM Match 360 - update to 4.7.0
python38-pyyaml - update to 5.4.1-1
python38-psutil - update to 5.6.4-4
python38-more-itertools - update to 7.2.0-5
python38-packaging - update to 19.2-3
python38-attrs - update to 19.3.0-3
python38-pip-wheel - update to 19.3.1-5
python38-pip - update to 19.3.1-5
python-pip-help - update to 20.2.2-6
python-pip - update to 20.2.2-6
python3-pip - update to 20.2.2-6
python-pip-wheel - update to 20.2.2-6
python2-pip - update to 20.2.2-6
python38-setuptools-wheel - update to 41.6.0-5
python38-setuptools - update to 41.6.0-5
python38-pytz - update to 2019.3-3
External References
Related Security Bulletins
- Denial of service in Python
- OpenSUSE Linux update for python3
- OpenSUSE Linux update for python3
- OpenSUSE Linux update for python-ipaddress
- OpenSUSE Linux update for python-ipaddress
- Gentoo update for Python
- Resource exhaustion in python3 (Alpine package)
- Amazon Linux AMI update for python34, python36, python35
- Red Hat Enterprise Linux 8 update for the python38:3.8 module
- Red Hat Enterprise Linux 8 update for python3
- Red Hat Enterprise Linux 7 update for python3
- CentOS 7 update for python3
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Platform
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- Resource exhaustion in IBM Match 360
- openEuler 20.03 LTS SP3 update for python-pip
- openEuler 20.03 LTS SP1 update for python-pip
- Ubuntu update for python3.10
- Anolis OS update for python38:3.8 module
- Ubuntu update for python2.7
- Fedora 31 update for python39
- Fedora 32 update for python39
- Fedora 32 update for mingw-python3
- Fedora 32 update for mingw-python3
- Fedora 32 update for python3, python3-docs
- Fedora 31 update for python38
- Fedora 31 update for python38
- Fedora 32 update for python3, python3-docs
- Fedora 32 update for python37
- Fedora 31 update for python3
- Fedora EPEL 7 update for python34
- Fedora 31 update for python36
- Fedora 32 update for python36
- Fedora 31 update for python35
- Fedora 32 update for python35
- Fedora 33 update for python3.5
- Fedora 34 update for python3.5
- Fedora 32 update for python34
- Dell RecoverPoint for Virtual Machines update for third-party components