Repository navigation
Race condition in the cleanup of tempfile.TemporaryDirectory #157579
Copy link
Copy link
Open
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixesstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-securityA security issueA security issue
Description
Activity
- addedtype-securityA security issueA security issuestdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory
on Sep 15, 2026 - added3.11only security fixesonly security fixes3.10 (EOL)end of lifeend of life3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixes
on Sep 15, 2026 - added a commit that references this issue
on Sep 29, 2026 TODO:
- this will need a fresh 3.12 backport PR.
- added a commit that references this issue
on Oct 2, 2026 - added a commit that references this issue
on Oct 3, 2026 What was the reason to revert the fix from 3.12? I see it was "merged prematurely" but is the fix somehow wrong?
We did a full sweep of 3.10-3.14 security releases last week, and we'd already started building (and iirc already completed one) without the fix, and it didn't seem quite right to only have the fix in 3.12.
https://blog.python.org/2026/10/python-31022-31117/
The fix itself looks fine, It'll likely be included for the next releases.
- added a commit that references this issue
on Oct 9, 2026
Metadata
Metadata
Assignees
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixesstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-securityA security issueA security issue
Projects
- StatusShow more project fieldsNo status
When working around file system permission errors, files are removed after resolving their path again, this means that by replacing a directory of the tree with a symbolic link, an attacker can make the cleanup delete files outside of the temporary directory.
Linked PRs
tempfile.TemporaryDirectory#157580tempfile.TemporaryDirectory(GH-157580) #158429tempfile.TemporaryDirectory(GH-157580) #158430tempfile.TemporaryDirectory(GH-157580) #158431tempfile.TemporaryDirectory(GH-157580) (GH-158430) #159074