Google: dev-lang/python: security update to 17162.210.44

critical Tenable Cloud Security Plugin ID 454700

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer
overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties.
This occurs in the sponge function interface. (CVE-2022-37454)

Solution

Update the dev-lang/python library and its related packages to version 17162.210.44 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-101.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 454700

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.37

Vendor

Vendor Severity: CRITICAL

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-37454

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 10/21/2022

Reference Information

CVE: CVE-2022-37454