Re: [LFS Trac] #5831: python3-3.14.1
| Newsgroups | gmane.linux.lfs.book |
|---|---|
| Message-ID | <[email protected]> |
#5831: python3-3.14.1
-------------------------+-----------------------
Reporter: Bruce Dubbs | Owner: lfs-book
Type: enhancement | Status: new
Priority: high | Milestone: 12.5
Component: Book | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-----------------------
Comment (by Douglas R. Reno):
{{{
{{{
-------- Forwarded Message --------
Subject: [Security-announce][CVE-2025-13836] Excessive read buffering DoS
in http.client
Date: Mon, 1 Dec 2025 18:57:32 +0000
From: Seth Larson <[email protected]>
Reply-To: [email protected]
To: [email protected]
There is a MEDIUM severity vulnerability affecting CPython.
When reading an HTTP response from a server, if no read amount is
specified, the
default behavior will be to use Content-Length. This allows a malicious
server
to cause the client to read large amounts of data into memory, potentially
causing OOM or other DoS.
Please see the linked CVE ID for the latest information on
affected versions:
* https://www.cve.org/CVERecord?id=CVE-2025-13836
* https://github.com/python/cpython/pull/119454
-------- Forwarded Message --------
Subject: [Security-announce][CVE-2025-13837] Out-of-memory when loading
Plist
Date: Mon, 1 Dec 2025 18:58:33 +0000
From: Seth Larson <[email protected]>
Reply-To: [email protected]
To: [email protected]
There is a LOW severity vulnerability affecting CPython.
When loading a plist file, the plistlib module reads data in size
specified by
the file itself, meaning a malicious file can cause OOM and DoS issues
Please see the linked CVE ID for the latest information on affected
versions:
* https://www.cve.org/CVERecord?id=CVE-2025-13837
* https://github.com/python/cpython/pull/119343
-------- Forwarded Message --------
Subject: [Security-announce][CVE-2025-12084] Quadratic complexity in node
ID cache clearing
Date: Wed, 3 Dec 2025 18:59:03 +0000
From: Seth Larson <[email protected]>
Reply-To: [email protected]
To: [email protected]
There is a MEDIUM severity vulnerability affecting CPython.
When building nested elements using xml.dom.minidom methods such as
appendChild() that have a dependency on _clear_id_cache() the algorithm is
quadratic. Availability can be impacted when building excessively nested
documents.
Please see the linked CVE ID for the latest information on affected
versions:
* https://www.cve.org/CVERecord?id=CVE-2025-12084
* https://github.com/python/cpython/pull/142146
}}}
}}}
--
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5831#comment:2>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.
--
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page