CVE-2022-48564

Updated: 2025-08-20 00:11:33.644366

Description:

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Alpine Linux 3.22 python 3.9 6.5 MEDIUM Not Vulnerable 2026-02-02 14:29:46 Not affected: the deployed Python 3.9.23 includes the upstream fix for the plistlib read_ints DoS (b...
Alpine Linux 3.22 python 3.7 6.5 MEDIUM Not Vulnerable 2026-02-16 14:40:00 Not affected: the deployed Python 3.9.23 includes the upstream fix for the plistlib read_ints DoS (b...
Alpine Linux 3.22 python 3.8 6.5 MEDIUM Not Vulnerable 2026-02-07 04:07:33 Not affected: the deployed Python 3.9.23 includes the upstream fix for the plistlib read_ints DoS (b...
Alpine Linux 3.22 python 3.6 6.5 MEDIUM Not Vulnerable 2026-01-27 16:42:58 Not affected: the deployed Python 3.9.23 includes the upstream fix for the plistlib read_ints DoS (b...
Debian 10 python 3.6 6.5 MEDIUM Already Fixed 2025-09-09 19:25:19
Debian 10 python 2.7 6.5 MEDIUM Not Vulnerable 2025-10-10 11:25:04
Debian 11 python 2.7 6.5 MEDIUM Not Vulnerable 2025-10-10 11:25:03
Debian 11 python 3.6 6.5 MEDIUM Already Fixed 2025-09-09 19:25:19
Debian 12 python 3.9 6.5 MEDIUM Not Vulnerable 2025-12-11 07:44:30 Not affected: the deployed Python 3.9.23 includes the upstream fix for the plistlib read_ints DoS (b...
Debian 12 python 3.7 6.5 MEDIUM Not Vulnerable 2025-12-11 07:45:17 Not affected: the deployed Python 3.9.23 includes the upstream fix for the plistlib read_ints DoS (b...
Total: 36