{
    "id": "CVE-2021-3177",
    "published": "2021-01-19 06:15:12",
    "last_modified": "2026-06-17 04:04:47",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-120",
    "description": "Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.",
    "epss_score": "0.23293",
    "epss_percentile": "0.97719",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-03 18:17:30",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 23.3% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "debian",
            "product": "debian_linux"
        },
        {
            "vendor": "fedoraproject",
            "product": "fedora"
        },
        {
            "vendor": "netapp",
            "product": "active_iq_unified_manager"
        },
        {
            "vendor": "netapp",
            "product": "ontap_select_deploy_administration_utility"
        },
        {
            "vendor": "oracle",
            "product": "communications_cloud_native_core_network_function_cloud_native_environment"
        },
        {
            "vendor": "oracle",
            "product": "communications_offline_mediation_controller"
        },
        {
            "vendor": "oracle",
            "product": "communications_pricing_design_center"
        },
        {
            "vendor": "oracle",
            "product": "enterprise_manager_ops_center"
        },
        {
            "vendor": "oracle",
            "product": "zfs_storage_appliance_kit"
        },
        {
            "vendor": "python",
            "product": "python"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://bugs.python.org/issue42938",
        "https://github.com/python/cpython/pull/24239",
        "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E",
        "https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html",
        "https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/",
        "https://news.ycombinator.com/item?id=26185005",
        "https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html",
        "https://security.gentoo.org/glsa/202101-18",
        "https://security.netapp.com/advisory/ntap-20210226-0003/",
        "https://www.oracle.com//security-alerts/cpujul2021.html"
    ]
}