CVE-2024-4032: Incorrect IPv4 and IPv6 private ranges

Published Jun 17, 2024
·
Updated

Incorrect IPv4 and IPv6 private ranges

Other sources

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the 'isprivate' and 'isglobal' properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.

CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.

References: https://github.com/python/cpython/issues/113171 https://github.com/python/cpython/pull/113179 https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml

Red Hat

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the isprivate and isglobal properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.

CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.

NVD

Affected Software

13 affected componentsFixes available
F5 BIG-IP=17.5.0, >=17.1.0<=17.1.2
F5 BIG-IP
debian/python2.7
2.7.18-8+deb11u1
debian/python3.11
3.11.2-6+deb12u53.11.2-6+deb12u3
debian/python3.12
3.12.10-1
debian/python3.13
3.13.3-2
debian/python3.9<=3.9.2-1
3.9.2-1+deb11u3
redhat/CPython<3.12.4
3.12.4
redhat/CPython<3.13.0
3.13.0
Microsoft azl3 python3 3.12.9-1
Microsoft cbl2 python3 3.9.19-13
Microsoft cbl2 python3 3.9.19-6
Microsoft azl3 python3 3.12.3-5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/python2.7 to a version that resolves this vulnerability.

    Fixed in 2.7.18-8+deb11u1
  2. Upgrade

    Upgrade debian/python3.11 to a version that resolves this vulnerability.

    Fixed in 3.11.2-6+deb12u5Fixed in 3.11.2-6+deb12u3
  3. Upgrade

    Upgrade debian/python3.12 to a version that resolves this vulnerability.

    Fixed in 3.12.10-1
  4. Upgrade

    Upgrade debian/python3.13 to a version that resolves this vulnerability.

    Fixed in 3.13.3-2
  5. Upgrade

    Upgrade debian/python3.9 to a version that resolves this vulnerability.

    Fixed in 3.9.2-1+deb11u3
  6. Upgrade

    Upgrade redhat/CPython to a version that resolves this vulnerability.

    Fixed in 3.12.4
  7. Upgrade

    Upgrade redhat/CPython to a version that resolves this vulnerability.

    Fixed in 3.13.0
  8. Upgrade

    Upgrade CPython to a version that resolves this vulnerability.

    Fixed in 3.12.4
  9. Upgrade

    Upgrade CPython to a version that resolves this vulnerability.

    Fixed in 3.13.0a6

Event History

Jun 17, 2024
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Jun 18, 2024
Data Sourced
via Red Hat·04:50 PM
DescriptionSeverityAffected Software
Jul 30, 2024
Data Sourced
via Launchpad·05:17 PM
Description
Oct 5, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Mar 12, 2025
Data Sourced
via Ubuntu·07:38 PM
RemedyDescriptionSeverityAffected Software
Apr 7, 2025
Advisory Published
via F5·10:59 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-4032?

CVE-2024-4032 is considered a moderate severity vulnerability affecting the ipaddress module's classification of IPv4 and IPv6 addresses.

2

How do I fix CVE-2024-4032?

To fix CVE-2024-4032, ensure you upgrade to the appropriate versions of CPython or Python as specified in the vulnerability report.

3

What versions of CPython are affected by CVE-2024-4032?

CVE-2024-4032 affects CPython versions below 3.12.4 and 3.13.0.

4

Is Python 3.9 impacted by CVE-2024-4032?

Yes, Python 3.9 is impacted by CVE-2024-4032 if it is up to version 3.9.2-1.

5

Which properties of the ipaddress module are affected by CVE-2024-4032?

CVE-2024-4032 affects the 'is_private' and 'is_global' properties of the ipaddress.IPv4Address and ipaddress.IPv6Address classes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203