USN-7464-1: Jupyter Notebook vulnerability
It was discovered that Jupyter Notebook did not properly parse HTML comments under certain circumstances. An attacker could possibly use this issue to cause a regular expression denial of service (ReDoS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7464-1?
The severity of USN-7464-1 is classified as medium, as it can lead to a regular expression denial of service (ReDoS) under specific circumstances.
How do I fix USN-7464-1?
To fix USN-7464-1, update the Jupyter Notebook to version 6.4.13-5ubuntu0.1 or a later version for the affected Ubuntu releases.
What versions are affected by USN-7464-1?
USN-7464-1 affects Jupyter Notebook versions below 6.4.13-5ubuntu0.1, specifically on Ubuntu versions 22.04, 24.04, 24.10, and 25.04.
What components are affected by USN-7464-1?
The affected components of USN-7464-1 include the jupyter-notebook and python3-notebook packages.
Is there any workaround for USN-7464-1?
There are no specific workarounds for USN-7464-1; the recommended action is to apply the software update.