ALAS2023-2026-1734


Amazon Linux 2023 Security Advisory: ALAS2023-2026-1734
Advisory Released Date: 2026-05-26
Advisory Updated Date: 2026-05-26
Severity: Important

Issue Overview:

The twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. (CVE-2026-42304)


Affected Packages:

python-twisted


Issue Correction:
Run dnf update python-twisted --releasever 2023.11.20260526 or dnf update --advisory ALAS2023-2026-1734 --releasever 2023.11.20260526 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
noarch:
    python3-twisted+tls-22.4.0-129.amzn2023.0.6.noarch
    python3-twisted-22.4.0-129.amzn2023.0.6.noarch

src:
    python-twisted-22.4.0-129.amzn2023.0.6.src