CVE-2022-48560: Debian Linux

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Python Python: before 3.6.11 (fixed in 3.6.11); from 3.7.0, before 3.7.7 (fixed in 3.7.7); from 3.8.0, before 3.8.2 (fixed in 3.8.2); version 3.9.0 only

Published 2023-08-22. Last modified 2026-06-17.