VAITP Dataset

← Back to the dataset

CVE-2024-3219

Local socket connection race vulnerability in Python's socket module.

  • CVSS 5.1
  • CWE-306
  • Race Conditions
  • Local

The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local connected pair of sockets. The connection between the two sockets was not verified before passing the two sockets back to the user, which leaves the server socket vulnerable to a connection race from a malicious local peer. Platforms that support AF_UNIX such as Linux and macOS are not affected by this vulnerability. Versions prior to CPython 3.5 are not affected due to the vulnerable API not being included.

CVSS base score
5.1
Published
2024-07-29
OWASP
A01 Broken Access Control
Orthogonal defect classification
Interface
Code defect classification
Incorrect Interface
Category
Race Conditions
Subcategory
Time-of-Check to Time-of-Use
Accessibility scope
Local
Impact
Unauthorized Access
Affected component
Python 3.5
Fixed by upgrading
Yes

Solution

Upgrade to CPython 3.5 or later to mitigate the vulnerability.

Vulnerable code sample

import socket

def create_socket_pair():
    """Vulnerable function that demonstrates the security issue."""
    # Create a pair of connected sockets using AF_INET
    sock1 = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
    sock2 = socket.socket(socket.AF_INET, socket.SOCK_STREAM)

    # Bind the sockets to localhost and a free port
    sock1.bind(('localhost', 0))
    sock2.bind(('localhost', 0))

    # Get the port number assigned to sock1
    port = sock1.getsockname()[1]

    # Here, the connection is not verified before returning the sockets
    sock2.connect(('localhost', port))

    return sock1, sock2

# Example usage
sock1, sock2 = create_socket_pair()
print("Socket pair created (vulnerable to connection race).")

Patched code sample

import socket

def create_socket_pair():
    """Secure function that fixes the vulnerability."""
    # Create a pair of connected sockets using AF_INET
    sock1 = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
    sock2 = socket.socket(socket.AF_INET, socket.SOCK_STREAM)

    # Bind the sockets to localhost and a free port
    sock1.bind(('localhost', 0))
    sock2.bind(('localhost', 0))

    # Get the port number assigned to sock1
    port = sock1.getsockname()[1]

    # Connect sock2 to sock1
    sock2.connect(('localhost', port))

    # Listen on sock1 to accept the connection from sock2
    sock1.listen(1)
    conn, _ = sock1.accept()

    return conn, sock2

# Example usage
conn, sock2 = create_socket_pair()
print("Connected sockets created successfully.")

Payload

import socket
import threading

# Malicious payload to exploit the connection race
def malicious_socket():
    # Create a socket and connect to the server socket
    sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
    sock.connect(('localhost', 12345))  # Assuming the server is bound to this port
    # Send malicious data
    sock.sendall(b'Malicious data')
    sock.close()

# Start the malicious thread
thread = threading.Thread(target=malicious_socket)
thread.start()

Cite this entry

@misc{vaitp:cve20243219,
  title        = {{Local socket connection race vulnerability in Python's socket module.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2024},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2024-3219},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2024-3219/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::