Описание
Security update for python-Twisted
This update for python-Twisted fixes the following issue
- CVE-2026-42304: Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression (bsc#1265265).
Список пакетов
openSUSE Leap 16.0
python-Twisted-doc-24.10.0-160000.3.1
python313-Twisted-24.10.0-160000.3.1
python313-Twisted-all_non_platform-24.10.0-160000.3.1
python313-Twisted-conch-24.10.0-160000.3.1
python313-Twisted-conch_nacl-24.10.0-160000.3.1
python313-Twisted-contextvars-24.10.0-160000.3.1
python313-Twisted-http2-24.10.0-160000.3.1
python313-Twisted-serial-24.10.0-160000.3.1
python313-Twisted-tls-24.10.0-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1265265
- SUSE CVE CVE-2026-42304 page
Описание
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
Затронутые продукты
openSUSE Leap 16.0:python-Twisted-doc-24.10.0-160000.3.1
openSUSE Leap 16.0:python313-Twisted-24.10.0-160000.3.1
openSUSE Leap 16.0:python313-Twisted-all_non_platform-24.10.0-160000.3.1
openSUSE Leap 16.0:python313-Twisted-conch-24.10.0-160000.3.1
Ссылки
- CVE-2026-42304
- SUSE Bug 1265265