[ubuntu/jammy-security] python-idna 3.3-1ubuntu0.2 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Wed Jul 15 13:41:54 UTC 2026
python-idna (3.3-1ubuntu0.2) jammy-security; urgency=medium
* SECURITY UPDATE: DoS via specially crafted inputs to idna.encode()
- debian/patches/CVE-2026-45409-1.patch: Reject oversized inputs up-front in
idna/core.py, tests/test_idna.py.
- debian/patches/CVE-2026-45409-2.patch: Use valid_string_length() for early
oversized-input check in idna/core.py.
- debian/patches/CVE-2026-45409-3.patch: Enforce early length limits in
check_label in idna/core.py, tests/test_idna.py.
- CVE-2026-45409
Date: 2026-07-14 18:24:12.264116+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/python-idna/3.3-1ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list