UBUNTU-CVE-2025-67725

Source
https://ubuntu.com/security/CVE-2025-67725
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67725.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-67725
Upstream
Downstream
Related
Published
2025-12-12T06:15:00Z
Modified
2026-01-14T03:20:45.703808Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using string concatenation when the same header name is repeated, causing a Denial of Service (DoS). Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity. The severity can vary from high if maxheadersize has been increased from its default, to low if it has its default value of 64KB. This issue is fixed in version 6.5.3.

References

Affected packages

Ubuntu:24.04:LTS

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@6.4.0-1ubuntu0.4?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-1ubuntu0.4

Affected versions

6.*

6.3.2-1
6.4.0-0ubuntu1
6.4.0-1
6.4.0-1build1
6.4.0-1ubuntu0.1
6.4.0-1ubuntu0.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-tornado",
            "binary_version": "6.4.0-1ubuntu0.4"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67725.json"

Ubuntu:25.04

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@6.4.2-1ubuntu0.25.04.3?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.2-1ubuntu0.25.04.3

Affected versions

6.*

6.4.1-2
6.4.1-3
6.4.2-1
6.4.2-1ubuntu0.25.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-tornado",
            "binary_version": "6.4.2-1ubuntu0.25.04.3"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67725.json"

Ubuntu:25.10

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@6.4.2-3ubuntu0.2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.2-3ubuntu0.2

Affected versions

6.*

6.4.2-1
6.4.2-2
6.4.2-2ubuntu1
6.4.2-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-tornado",
            "binary_version": "6.4.2-3ubuntu0.2"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67725.json"

Ubuntu:Pro:16.04:LTS

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@4.2.1-1ubuntu3.1+esm2?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.1-1ubuntu3.1+esm2

Affected versions

4.*

4.2.1-1ubuntu2
4.2.1-1ubuntu3
4.2.1-1ubuntu3.1
4.2.1-1ubuntu3.1+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python-tornado",
            "binary_version": "4.2.1-1ubuntu3.1+esm2"
        },
        {
            "binary_name": "python3-tornado",
            "binary_version": "4.2.1-1ubuntu3.1+esm2"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67725.json"

Ubuntu:Pro:18.04:LTS

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@4.5.3-1ubuntu0.2+esm2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.5.3-1ubuntu0.2+esm2

Affected versions

4.*

4.5.1-2.1~build2
4.5.2-1
4.5.3-1
4.5.3-1ubuntu0.1
4.5.3-1ubuntu0.2
4.5.3-1ubuntu0.2+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python-tornado",
            "binary_version": "4.5.3-1ubuntu0.2+esm2"
        },
        {
            "binary_name": "python3-tornado",
            "binary_version": "4.5.3-1ubuntu0.2+esm2"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67725.json"

Ubuntu:Pro:20.04:LTS

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@6.0.3+really5.1.1-3ubuntu0.1~esm3?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.3+really5.1.1-3ubuntu0.1~esm3

Affected versions

5.*

5.1.1-4ubuntu1
5.1.1-4ubuntu5

6.*

6.0.3+really5.1.1-2
6.0.3+really5.1.1-2build1
6.0.3+really5.1.1-2build2
6.0.3+really5.1.1-3
6.0.3+really5.1.1-3ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-tornado",
            "binary_version": "6.0.3+really5.1.1-3ubuntu0.1~esm3"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67725.json"

Ubuntu:Pro:22.04:LTS

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@6.1.0-3ubuntu0.1~esm4?arch=source&distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.0-3ubuntu0.1~esm4

Affected versions

6.*

6.1.0-1build1
6.1.0-2
6.1.0-3
6.1.0-3build1
6.1.0-3ubuntu0.1~esm1
6.1.0-3ubuntu0.1~esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-tornado",
            "binary_version": "6.1.0-3ubuntu0.1~esm4"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67725.json"