CVE-2022-48566: Debian Linux
Medium severity, CVSS 5.9. EPSS: 1.3% chance of exploitation in the next 30 days.
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
Affected products
- Debian Debian Linux: version 10.0 only
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Converged Systems Advisor Agent: affected versions not specified
- Python Python: before 3.6.13 (fixed in 3.6.13); from 3.7.0, before 3.7.10 (fixed in 3.7.10); from 3.8.0, before 3.8.7 (fixed in 3.8.7); from 3.9.0, before 3.9.1 (fixed in 3.9.1)
Published 2023-08-22. Last modified 2026-06-17.