A high severity vulnerability (CVE-2024-12254) has been discovered in CPython, affecting Python versions 3.12.0 and later.

The vulnerability is located in the asyncio module, and more specifically in the _SelectorSocketTransport.writelines() method. Under certain circumstances, this issue can cause a memory leak, posing a significant threat to the stability of applications that use this functionality.
Vulnerability Overview
See related: Critical vulnerability in IBM Db2 affects Linux and UNIX
The vulnerability results from incorrect memory handling in the `writelines()` method used in the `asyncio` module. It only affects users who meet all of the following criteria:
Normally, when the write buffer reaches a predefined limit ("high level"), the system temporarily stops the write process and alerts the protocol to flush the buffer, preventing excessive memory consumption. However, in Python 3.12.0 and later, this mechanism fails, allowing the write buffer to grow uncontrollably under certain conditions.
The issue is located in the operation of the `asyncio._SelectorSocketTransport.writelines()` method, which fails to stop the write process and flush the buffer when the predefined limit is reached. This malfunction can lead to uncontrolled memory consumption, increasing the risk of exhaustion of available resources. Due to its severity, this vulnerability has been classified as critical.
Read also: Hackers exploit vulnerability in Apple Safari
This vulnerability affects Python 3.12.0 and later on macOS and Linux systems. Specifically, `asyncio` protocols that use the `.writelines()` method may fail to flush the write buffer, due to the new zero-copy-on-write behavior introduced in Python 3.12.0.
Although the specific conditions for the vulnerability to manifest limit its scope, the risk of uncontrolled memory usage remains significant.
- Python versions: Use Python 3.12.0 or later.
- Operating Systems: Install on macOS or Linux.
- Module Usage: Active use of the asyncio module with protocols.
- Method Usage: Dependency on the .writelines() method, which introduced zero-copy-on-write behavior since Python 3.12.0.
See more: SolarWinds XSS vulnerability allows malware injection
If any of these conditions do not apply, then your use of Python will likely remain unaffected.

The Python development team is working hard to resolve the issue. A proposed fix is already under evaluation and is being considered via the relevant pull request.
What you can do:
Read more: Bootloader vulnerability affects over 100 Cisco Switches
- Installing Updates: Monitor the CVE listing and official Python repositories for security updates.
- Avoiding Affected Versions: If possible, revert to an older version of Python (before 3.12.0) that is not affected by the issue.
- Restrict Use of .writelines(): Avoid or replace use of the writelines() method in affected environments until the fix is implemented.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
