CVE-2026-3298

The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Apr 2026, 21:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/1274766d3c29007ab77245a72abbf8dce2a9db4d -
  • () https://github.com/python/cpython/commit/27522b7d6e6588f03e61099dd858cd5a9314e2f2 -
  • () https://github.com/python/cpython/commit/95633d2aad4721e25e4dfd9f43dfb6e1edcbd741 -

21 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 15:16

Updated : 2026-04-21 21:16


NVD link : CVE-2026-3298

Mitre link : CVE-2026-3298

CVE.ORG link : CVE-2026-3298


JSON object : View

Products Affected

No product.

CWE
CWE-787

Out-of-bounds Write