[CVE-2026-3298] Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
April 21, 2026
2:46 p.m.
There is a HIGH severity vulnerability affecting {project}.
The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected.
Please see the linked CVE ID for the latest information on affected versions:
144
Age (days ago)
144
Last active (days ago)
0 comments
1 participants
participants (1)
-
Seth Larson