Re: [LFS Trac] #5831: python3-3.14.1

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5831: python3-3.14.1
-------------------------+-----------------------
 Reporter:  Bruce Dubbs  |       Owner:  lfs-book
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  12.5
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-----------------------
Comment (by Douglas R. Reno):

 {{{

 {{{
 -------- Forwarded Message --------
 Subject: [Security-announce][CVE-2025-13836] Excessive read buffering DoS
 in http.client
 Date:     Mon, 1 Dec 2025 18:57:32 +0000
 From:     Seth Larson <[email protected]>
 Reply-To:     [email protected]
 To:     [email protected]



 There is a MEDIUM severity vulnerability affecting CPython.

 When reading an HTTP response from a server, if no read amount is
 specified, the
 default behavior will be to use Content-Length. This allows a malicious
 server
 to cause the client to read large amounts of data into memory, potentially
 causing OOM or other DoS.

 Please see the linked CVE ID for the latest information on
 affected versions:

 * https://www.cve.org/CVERecord?id=CVE-2025-13836
 * https://github.com/python/cpython/pull/119454


 -------- Forwarded Message --------
 Subject: [Security-announce][CVE-2025-13837] Out-of-memory when loading
 Plist
 Date:     Mon, 1 Dec 2025 18:58:33 +0000
 From:     Seth Larson <[email protected]>
 Reply-To:     [email protected]
 To:     [email protected]



 There is a LOW severity vulnerability affecting CPython.

 When loading a plist file, the plistlib module reads data in size
 specified by
 the file itself, meaning a malicious file can cause OOM and DoS issues

 Please see the linked CVE ID for the latest information on affected
 versions:

 * https://www.cve.org/CVERecord?id=CVE-2025-13837
 * https://github.com/python/cpython/pull/119343


 -------- Forwarded Message --------
 Subject: [Security-announce][CVE-2025-12084] Quadratic complexity in node
 ID cache clearing
 Date:     Wed, 3 Dec 2025 18:59:03 +0000
 From:     Seth Larson <[email protected]>
 Reply-To:     [email protected]
 To:     [email protected]



 There is a MEDIUM severity vulnerability affecting CPython.

 When building nested elements using xml.dom.minidom methods such as
 appendChild() that have a dependency on _clear_id_cache() the algorithm is
 quadratic. Availability can be impacted when building excessively nested
 documents.

 Please see the linked CVE ID for the latest information on affected
 versions:

 * https://www.cve.org/CVERecord?id=CVE-2025-12084
 * https://github.com/python/cpython/pull/142146
 }}}

 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5831#comment:2>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.