CVE-2024-4032

Updated: 2025-08-20 02:31:27.584079

Description:

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x LOW 3.7

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU python3.11 3.11.2 3.7 LOW Released CLSA-2025:1741126677 2025-03-05 21:53:15
AlmaLinux 9.2 ESU python3 3.9.16 3.7 LOW Released CLSA-2024:1727374287 2024-09-26 14:34:22
CentOS 6 ELS python 2.6.6 3.7 LOW Ignored 2024-08-29 12:10:11 Ignored due to low severity
CentOS 7 ELS python 2.7.5 3.7 LOW Ignored 2024-08-29 12:10:11 Ignored due to low severity
CentOS 7 ELS python3 3.6.8 3.7 LOW Ignored 2024-07-24 05:16:54 Ignored due to low severity
CentOS 8.4 ELS python3 3.6.8 3.7 LOW Released CLSA-2024:1728403634 2024-10-08 14:36:48
CentOS 8.4 ELS python2 2.7.18 3.7 LOW Not Vulnerable 2024-09-25 12:31:10
CentOS 8.5 ELS python2 2.7.18 3.7 LOW Not Vulnerable 2024-09-25 12:31:10
CentOS 8.5 ELS python3 3.6.8 3.7 LOW Released CLSA-2024:1728404424 2024-10-08 14:36:47
CentOS Stream 8 ELS python2 2.7.18 3.7 LOW Not Vulnerable 2024-09-25 12:31:10
Total: 15