Описание
Security update for python3-Twisted
This update for python3-Twisted fixes the following issue
- CVE-2026-42304: Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression (bsc#1265265).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise Module for Server Applications 15 SP7
python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise Server 15 SP4-LTSS
python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise Server 15 SP5-LTSS
python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise Server 15 SP6-LTSS
python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
python3-Twisted-22.2.0-150400.24.1
Ссылки
- Link for SUSE-SU-2026:2218-1
- E-Mail link for SUSE-SU-2026:2218-1
- SUSE Security Ratings
- SUSE Bug 1265265
- SUSE CVE CVE-2026-42304 page
Описание
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:python3-Twisted-22.2.0-150400.24.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:python3-Twisted-22.2.0-150400.24.1
Ссылки
- CVE-2026-42304
- SUSE Bug 1265265