Advisory Published
Updated

REDHAT-BUG-1854926

First published: Wed Jul 08 2020(Updated: )

A vulnerability was found in Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. References: <a href="https://bugs.python.org/issue41004">https://bugs.python.org/issue41004</a> <a href="https://github.com/python/cpython/pull/20956">https://github.com/python/cpython/pull/20956</a>

Affected SoftwareAffected VersionHow to fix
Python Babel Localedata<=3.8.3

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-1854926?

    The severity of REDHAT-BUG-1854926 is classified as high due to its potential for causing a denial of service.

  • How do I fix REDHAT-BUG-1854926?

    To fix REDHAT-BUG-1854926, upgrade Python to version 3.8.4 or later where the vulnerability has been resolved.

  • What impact does REDHAT-BUG-1854926 have on applications?

    REDHAT-BUG-1854926 can negatively affect applications by causing degraded performance and possible denial of service when handling IPv4Interface and IPv6Interface classes.

  • Which versions of Python are affected by REDHAT-BUG-1854926?

    REDHAT-BUG-1854926 affects Python versions up to and including 3.8.3.

  • Who can be affected by REDHAT-BUG-1854926?

    Any application that uses the affected Python version for processing IP addresses may be vulnerable to REDHAT-BUG-1854926.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203