CVE-2014-2667: Python

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.

Affected products

  • Python Python: version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.2.4 only; version 3.2.5 only; …

Published 2014-11-16. Last modified 2026-06-17.