[ubuntu/resolute-security] python-idna 3.11-1ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Jul 15 13:41:49 UTC 2026


python-idna (3.11-1ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: DoS via specially crafted inputs to idna.encode()
    - debian/patches/CVE-2026-45409-1.patch: Reject oversized inputs up-front in
      idna/core.py, tests/test_idna.py.
    - debian/patches/CVE-2026-45409-2.patch: Use valid_string_length() for early
      oversized-input check in idna/core.py.
    - debian/patches/CVE-2026-45409-3.patch: Enforce early length limits in
      check_label in idna/core.py, tests/test_idna.py.
    - CVE-2026-45409

Date: 2026-07-14 18:06:17.990650+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/python-idna/3.11-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list