{"id":"UBUNTU-CVE-2026-5713","details":"The \"profiling.sampling\" module (Python 3.15+) and \"asyncio introspection capabilities\" (3.14+, \"python -m asyncio ps\" and \"python -m asyncio pstree\") features could be used to read and write addresses in a privileged process if that process connected to a malicious or \"infected\" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.","modified":"2026-07-06T16:03:43.941066184Z","published":"2026-04-14T16:16:00Z","related":["USN-8509-1"],"upstream":["CVE-2026-5713"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-5713"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-5713"},{"type":"REPORT","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8509-1"}],"affected":[{"package":{"name":"python3.14","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/python3.14?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.14.0~a7-0ubuntu1","3.14.0~b1-1","3.14.0~b3-1","3.14.0~rc1-1","3.14.0~rc2-1","3.14.0~rc3-1","3.14.0-1","3.14.0-1ubuntu0.1","3.14.0-1ubuntu0.2","3.14.0-1ubuntu0.3"],"ecosystem_specific":{"binaries":[{"binary_version":"3.14.0-1ubuntu0.3","binary_name":"idle-python3.14"},{"binary_name":"libpython3.14","binary_version":"3.14.0-1ubuntu0.3"},{"binary_name":"libpython3.14-minimal","binary_version":"3.14.0-1ubuntu0.3"},{"binary_name":"libpython3.14-stdlib","binary_version":"3.14.0-1ubuntu0.3"},{"binary_version":"3.14.0-1ubuntu0.3","binary_name":"libpython3.14-testsuite"},{"binary_version":"3.14.0-1ubuntu0.3","binary_name":"python3.14"},{"binary_name":"python3.14-examples","binary_version":"3.14.0-1ubuntu0.3"},{"binary_name":"python3.14-full","binary_version":"3.14.0-1ubuntu0.3"},{"binary_version":"3.14.0-1ubuntu0.3","binary_name":"python3.14-gdbm"},{"binary_name":"python3.14-minimal","binary_version":"3.14.0-1ubuntu0.3"},{"binary_name":"python3.14-nopie","binary_version":"3.14.0-1ubuntu0.3"},{"binary_version":"3.14.0-1ubuntu0.3","binary_name":"python3.14-tk"},{"binary_name":"python3.14-venv","binary_version":"3.14.0-1ubuntu0.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5713.json"}},{"package":{"name":"python3.14","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/python3.14?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.14.4-1ubuntu0.1"}]}],"versions":["3.14.0-1","3.14.0-2","3.14.0-4","3.14.2-1","3.14.3-1","3.14.3-2","3.14.3-3","3.14.3-5","3.14.4-1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.14.4-1ubuntu0.1","binary_name":"idle-python3.14"},{"binary_version":"3.14.4-1ubuntu0.1","binary_name":"libpython3.14"},{"binary_version":"3.14.4-1ubuntu0.1","binary_name":"libpython3.14-minimal"},{"binary_version":"3.14.4-1ubuntu0.1","binary_name":"libpython3.14-stdlib"},{"binary_name":"libpython3.14-testsuite","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-examples","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-full","binary_version":"3.14.4-1ubuntu0.1"},{"binary_version":"3.14.4-1ubuntu0.1","binary_name":"python3.14-gdbm"},{"binary_version":"3.14.4-1ubuntu0.1","binary_name":"python3.14-minimal"},{"binary_name":"python3.14-nopie","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-tk","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-venv","binary_version":"3.14.4-1ubuntu0.1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5713.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]}