CVE-2024-3219
Local socket connection race vulnerability in Python's socket module.
- CVSS 5.1
- CWE-306
- Race Conditions
- Local
The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local connected pair of sockets. The connection between the two sockets was not verified before passing the two sockets back to the user, which leaves the server socket vulnerable to a connection race from a malicious local peer. Platforms that support AF_UNIX such as Linux and macOS are not affected by this vulnerability. Versions prior to CPython 3.5 are not affected due to the vulnerable API not being included.
- CWE
- CWE-306
- CVSS base score
- 5.1
- Published
- 2024-07-29
- OWASP
- A01 Broken Access Control
- Orthogonal defect classification
- Interface
- Code defect classification
- Incorrect Interface
- Category
- Race Conditions
- Subcategory
- Time-of-Check to Time-of-Use
- Accessibility scope
- Local
- Impact
- Unauthorized Access
- Affected component
- Python 3.5
- Fixed by upgrading
- Yes
Solution
Upgrade to CPython 3.5 or later to mitigate the vulnerability.
Vulnerable code sample
import socket
def create_socket_pair():
"""Vulnerable function that demonstrates the security issue."""
# Create a pair of connected sockets using AF_INET
sock1 = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock2 = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
# Bind the sockets to localhost and a free port
sock1.bind(('localhost', 0))
sock2.bind(('localhost', 0))
# Get the port number assigned to sock1
port = sock1.getsockname()[1]
# Here, the connection is not verified before returning the sockets
sock2.connect(('localhost', port))
return sock1, sock2
# Example usage
sock1, sock2 = create_socket_pair()
print("Socket pair created (vulnerable to connection race).")Patched code sample
import socket
def create_socket_pair():
"""Secure function that fixes the vulnerability."""
# Create a pair of connected sockets using AF_INET
sock1 = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock2 = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
# Bind the sockets to localhost and a free port
sock1.bind(('localhost', 0))
sock2.bind(('localhost', 0))
# Get the port number assigned to sock1
port = sock1.getsockname()[1]
# Connect sock2 to sock1
sock2.connect(('localhost', port))
# Listen on sock1 to accept the connection from sock2
sock1.listen(1)
conn, _ = sock1.accept()
return conn, sock2
# Example usage
conn, sock2 = create_socket_pair()
print("Connected sockets created successfully.")Payload
import socket
import threading
# Malicious payload to exploit the connection race
def malicious_socket():
# Create a socket and connect to the server socket
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.connect(('localhost', 12345)) # Assuming the server is bound to this port
# Send malicious data
sock.sendall(b'Malicious data')
sock.close()
# Start the malicious thread
thread = threading.Thread(target=malicious_socket)
thread.start()
Cite this entry
@misc{vaitp:cve20243219,
title = {{Local socket connection race vulnerability in Python's socket module.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2024},
note = {VAITP Python Vulnerability Dataset, entry CVE-2024-3219},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2024-3219/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
