HomeDefectsLIN1024-342
Acknowledged

LIN1024-342 : Security Advisory - python - CVE-2023-6597

Created: Apr 29, 2024    Updated: Jan 7, 2026
Resolved Date: Jul 22, 2024
Found In Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior.

The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.

https://nvd.nist.gov/vuln/detail/CVE-2023-6597