[ubuntu/jammy-security] python-idna 3.3-1ubuntu0.2 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Jul 15 13:41:54 UTC 2026


python-idna (3.3-1ubuntu0.2) jammy-security; urgency=medium

  * SECURITY UPDATE: DoS via specially crafted inputs to idna.encode()
    - debian/patches/CVE-2026-45409-1.patch: Reject oversized inputs up-front in
      idna/core.py, tests/test_idna.py.
    - debian/patches/CVE-2026-45409-2.patch: Use valid_string_length() for early
      oversized-input check in idna/core.py.
    - debian/patches/CVE-2026-45409-3.patch: Enforce early length limits in
      check_label in idna/core.py, tests/test_idna.py.
    - CVE-2026-45409

Date: 2026-07-14 18:24:12.264116+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/python-idna/3.3-1ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list