INFSA-2024:3846: python-idna security update

Information about definition

Identificator: INFSA-2024:3846

Type: security

Release date: 2024-12-27 09:24:49 UTC

Information about package

The hsakmt packages include a thunk library for AMD's Heterogeneous System Architecture (HSA) Linux kernel driver (amdkfd).

Vulnerabilities description

  • CVE-2024-3651

    A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the `idna.encode()` function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2024-3651
no information 6.5 no information
Critical, important, moderate, low

Updated packages