USN-7219-1: Python vulnerability
USN-7219-1: Python vulnerability
20 January 2025
Python could be made to consume resources if it received specially crafted network traffic.
Releases
Ubuntu 24.10 Ubuntu 24.04 LTS
Packages
python3.12 - An interactive high-level object-oriented language
Details
It was discovered that Python incorrectly handled asyncio write buffers. A
remote attacker could possibly use this issue to cause Python to consume
memory, leading to a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
- python3.12 - 3.12.7-1ubuntu1.1
- python3.12-minimal - 3.12.7-1ubuntu1.1
Ubuntu 24.04 - python3.12 - 3.12.3-1ubuntu0.4
- python3.12-minimal - 3.12.3-1ubuntu0.4
In general, a standard system update will make all the necessary changes.