Intel

AIKIDO-2024-10156

pybind11 is vulnerable to Use-After-Free

Use-After-Free Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 28, 2024

30

Low Risk

This Affects:

pythonpybind11
0.1.0 - 2.12.0
Fixed in 2.13.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a use-after-free vulnerability due to a reference count bug.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

pybind11 is vulnerable to Use-After-Free in versions 0.1.0 - 2.12.0.

How to fix this

Upgrade pybind11 to a patch version.