First published: Mon Apr 28 2025(Updated: )
It was discovered that Jupyter Notebook did not properly parse HTML comments under certain circumstances. An attacker could possibly use this issue to cause a regular expression denial of service (ReDoS).
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/jupyter-notebook | <6.4.13-5ubuntu0.1 | 6.4.13-5ubuntu0.1 |
Ubuntu | =25.04 | |
All of | ||
ubuntu/python3-notebook | <6.4.13-5ubuntu0.1 | 6.4.13-5ubuntu0.1 |
Ubuntu | =25.04 | |
All of | ||
ubuntu/jupyter-notebook | <6.4.13-2ubuntu0.1 | 6.4.13-2ubuntu0.1 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/python3-notebook | <6.4.13-2ubuntu0.1 | 6.4.13-2ubuntu0.1 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/jupyter-notebook | <6.4.12-2.2ubuntu1+esm1 | 6.4.12-2.2ubuntu1+esm1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/python3-notebook | <6.4.12-2.2ubuntu1+esm1 | 6.4.12-2.2ubuntu1+esm1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/jupyter-notebook | <6.4.8-1ubuntu0.1+esm1 | 6.4.8-1ubuntu0.1+esm1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/python3-notebook | <6.4.8-1ubuntu0.1+esm1 | 6.4.8-1ubuntu0.1+esm1 |
Ubuntu | =22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7464-1 is classified as medium, as it can lead to a regular expression denial of service (ReDoS) under specific circumstances.
To fix USN-7464-1, update the Jupyter Notebook to version 6.4.13-5ubuntu0.1 or a later version for the affected Ubuntu releases.
USN-7464-1 affects Jupyter Notebook versions below 6.4.13-5ubuntu0.1, specifically on Ubuntu versions 22.04, 24.04, 24.10, and 25.04.
The affected components of USN-7464-1 include the jupyter-notebook and python3-notebook packages.
There are no specific workarounds for USN-7464-1; the recommended action is to apply the software update.