{"id":"USN-8776-1","summary":"python-cryptography vulnerabilities","details":"It was discovered that python-cryptography incorrectly accepted objects\nwith immutable buffers when performing certain cipher operations. This\nwould result in corrupted output, contrary to expectations. This issue only\naffected Ubuntu 18.04 LTS. (CVE-2023-23931)\n\nIt was discovered that python-cryptography reported the outcome of\ndecrypting PKCS#7 enveloped data in distinguishable ways, and with\nobservable timing differences. A remote attacker could possibly use this\nissue to recover the key used to encrypt the message contents, and obtain\nsensitive information. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-69247)\n\nJack Lloyd discovered that python-cryptography incorrectly handled wildcard\nDNS names when enforcing the name constraints of a certificate authority. A\nremote attacker could possibly use this issue to have an invalid\ncertificate chain accepted, and use names outside of the permitted ones.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248)\n\nSamuel Judson discovered that python-cryptography incorrectly handled\ncertificate chains that contained duplicate certificates. A remote attacker\ncould possibly use this issue to cause python-cryptography to use excessive\nresources, leading to a denial of service. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-69249)","modified":"2026-09-17T02:57:29.187283846Z","published":"2026-09-16T20:12:52Z","upstream":["CVE-2023-23931","CVE-2026-69247","CVE-2026-69248","CVE-2026-69249","UBUNTU-CVE-2023-23931","UBUNTU-CVE-2026-69247","UBUNTU-CVE-2026-69248","UBUNTU-CVE-2026-69249"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8776-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-23931"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-69247"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-69248"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-69249"}],"affected":[{"package":{"name":"python-cryptography","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/python-cryptography?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.4-1ubuntu1.4+esm6"}]}],"versions":["1.9-1","2.1.3-3","2.1.4-1","2.1.4-1build1","2.1.4-1build2","2.1.4-1ubuntu1","2.1.4-1ubuntu1.1","2.1.4-1ubuntu1.2","2.1.4-1ubuntu1.3","2.1.4-1ubuntu1.4","2.1.4-1ubuntu1.4+esm1","2.1.4-1ubuntu1.4+esm3"],"ecosystem_specific":{"binaries":[{"binary_name":"python-cryptography","binary_version":"2.1.4-1ubuntu1.4+esm6"},{"binary_name":"python3-cryptography","binary_version":"2.1.4-1ubuntu1.4+esm6"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8776-1.json"}},{"package":{"name":"python-cryptography","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/python-cryptography?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"46.0.5-1ubuntu2.2"}]}],"versions":["43.0.0-1ubuntu1","46.0.1-1ubuntu2","46.0.5-1ubuntu1","46.0.5-1ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-cryptography","binary_version":"46.0.5-1ubuntu2.2"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8776-1.json","cves_map":{"cves":[],"ecosystem":"Ubuntu:26.04:LTS"}}}],"schema_version":"1.9.0"}