{"id":"CVE-2024-9979","aliases":["GHSA-6jgw-rgmm-7cv6","RUSTSEC-2024-0378"],"url":"https://o3.security/vulnerability/CVE-2024-9979","summary":"Pyo3: risk of use-after-free in `borrowed` reads from python weak references","details":"A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or crashes via unsound borrowing from weak Python references.","published":"2024-10-15T14:01:54.309Z","modified":"2026-09-15T11:30:40.981168799Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"pyo3","fixedVersion":"0.22.4"}],"fix":{"url":"https://github.com/PyO3/pyo3/pull/4590","label":"PyO3/pyo3#4590"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://crates.io/crates/pyo3"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2024-9979"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9979.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9979"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2024-0378.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2318646"},{"type":"FIX","url":"https://github.com/PyO3/pyo3/pull/4590"},{"type":"PACKAGE","url":"https://github.com/PyO3/pyo3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-15T11:30:40.981168799Z"}}