The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
{ "binaries": [ { "binary_version": "1.0.3-1build2", "binary_name": "python-rencode" }, { "binary_version": "1.0.3-1build2", "binary_name": "python3-rencode" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-40839.json"
{ "binaries": [ { "binary_version": "1.0.5-1build2", "binary_name": "python-rencode" }, { "binary_version": "1.0.5-1build2", "binary_name": "python3-rencode" } ] }
{ "binaries": [ { "binary_version": "1.0.6-1build1", "binary_name": "python3-rencode" } ] }
{ "binaries": [ { "binary_version": "1.0.6-2build1", "binary_name": "python3-rencode" } ] }