python-idna-2.10-8.el9_8

エラータID: AXSA:2026-1620:02

リリース日: 
2026/08/23 Sunday - 13:18
題名: 
python-idna-2.10-8.el9_8
影響のあるチャネル: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

* python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-45409
Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. python-idna-2.10-8.el9_8.src.rpm
    MD5: cb8698fb7d530ab639a5d865c8187fd3
    SHA-256: 0083103d03537872ba6a883ff78a080c243a7521593538bb693bb229f233c7dc
    Size: 191.21 kB

Asianux Server 9 for x86_64
  1. python3-idna-2.10-8.el9_8.noarch.rpm
    MD5: bbf4bc9ed254c11e9bba672f5fe32546
    SHA-256: cf612566d285bbed24de6ad512a183f0588ebef96621f8043f7518e078fd5a59
    Size: 105.52 kB