Zurück zur Liste

AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups — GHSA-3W57-8XMC-8V26

GitHub · GitHub · GHSA-3W57-8XMC-8V26

ID
GHSA-3W57-8XMC-8V26
Datum
Quelle
GitHub
Vendor
GitHub
Risiko
hoch
CVSS
7

Zusammenfassung

AnyIO 4.14.0 accepts the POSIX extra_groups argument on anyio.run_process() and anyio.open_process(), but open_process() forwards the wrong variable to the backend: when extra_groups is not None, it assigns kwargs["extra_groups"] = group instead of extra_groups. As a result, callers cannot reliably clear or set supplementary groups for child processes. In a disposable Linux container, Python's subprocess.run(...,…

Zeitlicher Verlauf

Von der Quelle veröffentlicht
2026-09-18

Risikokontext

  • Gemeldeter Schweregrad oder Risikowert: hoch.
  • Gemeldeter CVSS-Wert: 7 von 10.
  • Prüfe die Exponierung für das betroffene Produkt oder die Produktfamilie: pip: anyio.

Produkt

pip: anyio

Was tun?

Allgemeine, vorsichtige Schritte (bitte prüfe die offizielle Quelle für Details):

  • Priorisiere sofort Patches oder Mitigations (hohes akutes Risiko).
  • Identifiziere betroffene Produktversionen und prüfe, ob du betroffen bist.
  • Spiele Hersteller-Updates/Patches ein oder setze empfohlene Mitigations um.
  • Lies das offizielle Advisory für betroffene Versionen und konkrete Schritte.

Offizielles Advisory

Nachweise und Herkunft

Kanonische Advisory-ID
GHSA-3W57-8XMC-8V26
Quelle
GitHub
Vendor
GitHub
Von der Quelle veröffentlicht
2026-09-18
Letzte Quellenaktivität
2026-09-18
Weitere Kennungen
CVE-2026-63349
Kuratiert von
hlukh.ch

Verwandte Hinweise und Zusammenhänge

Diese Hinweise sind anhand gemeinsamer CVE-, Produkt-, Hersteller-, Quellen- oder Zeitsignale verknüpft.