USN-7219-1: Python vulnerability
Published Jan 20, 2025
·Updated
It was discovered that Python incorrectly handled asyncio write buffers. A remote attacker could possibly use this issue to cause Python to consume memory, leading to a denial of service.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/python3.12<3.12.7-1ubuntu1.1
3.12.7-1ubuntu1.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/python3.12-minimal<3.12.7-1ubuntu1.1
3.12.7-1ubuntu1.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/python3.12<3.12.3-1ubuntu0.4
3.12.3-1ubuntu0.4
Ubuntu Ubuntu=24.04
All of the following
ubuntu/python3.12-minimal<3.12.3-1ubuntu0.4
3.12.3-1ubuntu0.4
Ubuntu Ubuntu=24.04
Event History
Jan 20, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7219-1?
The security issue identified in USN-7219-1 is classified as a moderate severity vulnerability.
2
How do I fix USN-7219-1?
To remediate USN-7219-1, update Python 3.12 to version 3.12.7-1ubuntu1.1 or 3.12.3-1ubuntu0.4 depending on your Ubuntu release.
3
Which versions of Ubuntu are affected by USN-7219-1?
USN-7219-1 affects Ubuntu 24.10 and Ubuntu 24.04 with specific versions of Python 3.12.
4
What type of vulnerability is USN-7219-1?
USN-7219-1 is a denial of service vulnerability caused by improper handling of asyncio write buffers in Python.
5
Can USN-7219-1 be exploited remotely?
Yes, USN-7219-1 can potentially be exploited by a remote attacker to cause memory consumption leading to denial of service.