|
|
Log in / Subscribe / Register

Ubuntu alert USN-7950-1 (python-tornado)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7950-1] Tornado vulnerabilities
Date:  Thu, 08 Jan 2026 20:43:43 +0000
Message-ID:  <E1vdwr9-0001eR-8M@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7950-1 January 08, 2026 python-tornado vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Tornado. Software Description: - python-tornado: scalable, non-blocking web server and tools Details: It was discovered that Tornado incorrectly handled special characters in HTTP headers. An attacker could possibly use this issue to execute a cross- site scripting (XSS) attack. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.04, and Ubuntu 25.10. (CVE-2025-67724) It was discovered that Tornado incorrectly handled repeated HTTP headers. An attacker could possibly use this issue to cause Tornado to use excessive resources, causing a denial of service. (CVE-2025-67725) It was discovered that Tornado incorrectly handled parsing of certain HTTP header values. An attacker could possibly use this issue to cause Tornado to use excessive resources, causing a denial of service. (CVE-2025-67726) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 python3-tornado 6.4.2-3ubuntu0.2 Ubuntu 25.04 python3-tornado 6.4.2-1ubuntu0.25.04.3 Ubuntu 24.04 LTS python3-tornado 6.4.0-1ubuntu0.4 Ubuntu 22.04 LTS python3-tornado 6.1.0-3ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 20.04 LTS python3-tornado 6.0.3+really5.1.1-3ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS python-tornado 4.5.3-1ubuntu0.2+esm2 Available with Ubuntu Pro python3-tornado 4.5.3-1ubuntu0.2+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS python-tornado 4.2.1-1ubuntu3.1+esm2 Available with Ubuntu Pro python3-tornado 4.2.1-1ubuntu3.1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7950-1 CVE-2025-67724, CVE-2025-67725, CVE-2025-67726 Package Information: https://launchpad.net/ubuntu/+source/python-tornado/6.4.2... https://launchpad.net/ubuntu/+source/python-tornado/6.4.2... https://launchpad.net/ubuntu/+source/python-tornado/6.4.0...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmlgFs0ACgkQcpJm3tlz hgFNeBAAym3b17ESR/jvrjGNIbzSwz2tJDn62cRTXKc/UQJzHCQNa7VE9vnEhfEu KrIWFplRp/FHvJ9Zl7gh7hOpLi2WbXoSaOEBkXcxjVEbYaVB0x1DID4cKq5KBtHS Db2Vk0SUhy6+uqucAnJhtxIPalrUNKZk5TZTmMwEIZ4t8xLWN2FpB8mG8lpOW5zS lsZ9m7gkBRK+ZdunRAeDzS//T0+ejRC+XAOlrw5pTaACHPFmT8pWsasMZmPMADjF hW6CNX86ckdw2M+XhuTRK+PTbV2g8P2J1KMeYatdlGsJO4swqZysSdUKw1yNnyt0 bpysyc4ev9YH6T8avG18Mz5xhoS0aNzie4F1oHY1PRQP9M40z1586SsTUKH5VZxc DBrUfTxdrJ1W7NTYr/TAZ9RGOY8VVRIcbFTaxjF0QynH/AzrWG1KwOaJFqn8S+ti lPYbFDFXOAE0HLm8TOvF0daVAJJQN2gPb00FDILSw1YjMALuJRaDqCk9kpbPLhP5 7l9CDJfVwRhZOhBNfdgCKCZ6LTxC+8euNG1tBJddA7rNGzSzUErpR/T8Uxix9ey6 cCUbf8l2AqZ9RK2qEON+uLP3Iae3a6T6LyzZjERPc05I/ju8mOlbIFb+zEUiRN1y ZHF0OT30IAPR13PUNJLM/8SfwSpdOAmAQ7Ru32QsJm1X1V8SnP8= =zgN5 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds