USN-8776-1
Dashboard / Vulnerabilities / USN-8776-1
USN-8776-1
Summary: python-cryptography vulnerabilities
Details: It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectations. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-23931) It was discovered that python-cryptography reported the outcome of decrypting PKCS#7 enveloped data in distinguishable ways, and with observable timing differences. A remote attacker could possibly use this issue to recover the key used to encrypt the message contents, and obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69247) Jack Lloyd discovered that python-cryptography incorrectly handled wildcard DNS names when enforcing the name constraints of a certificate authority. A remote attacker could possibly use this issue to have an invalid certificate chain accepted, and use names outside of the permitted ones. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248) Samuel Judson discovered that python-cryptography incorrectly handled certificate chains that contained duplicate certificates. A remote attacker could possibly use this issue to cause python-cryptography to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69249)
References: https://ubuntu.com/security/notices/USN-8776-1, https://ubuntu.com/security/CVE-2023-23931, https://ubuntu.com/security/CVE-2026-69247, https://ubuntu.com/security/CVE-2026-69248, https://ubuntu.com/security/CVE-2026-69249
Affected packages
Package
Name: python-cryptography
Purl: pkg:deb/ubuntu/python-cryptography?arch=source&distro=esm-infra%2Fbionic
Affected ranges
Type: ECOSYSTEM
Events:
