{"id":"USN-8776-1","summary":"python-cryptography vulnerabilities","details":"It was discovered that python-cryptography incorrectly accepted objects\nwith immutable buffers when performing certain cipher operations. This\nwould result in corrupted output, contrary to expectations. This issue only\naffected Ubuntu 18.04 LTS. (CVE-2023-23931)\n\nIt was discovered that python-cryptography reported the outcome of\ndecrypting PKCS#7 enveloped data in distinguishable ways, and with\nobservable timing differences. A remote attacker could possibly use this\nissue to recover the key used to encrypt the message contents, and obtain\nsensitive information. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-69247)\n\nJack Lloyd discovered that python-cryptography incorrectly handled wildcard\nDNS names when enforcing the name constraints of a certificate authority. A\nremote attacker could possibly use this issue to have an invalid\ncertificate chain accepted, and use names outside of the permitted ones.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248)\n\nSamuel Judson discovered that python-cryptography incorrectly handled\ncertificate chains that contained duplicate certificates. A remote attacker\ncould possibly use this issue to cause python-cryptography to use excessive\nresources, leading to a denial of service. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-69249)","modified":"2026-09-17T20:11:43.487622221Z","published":"2026-09-16T20:12:52Z","related":["UBUNTU-CVE-2023-23931","UBUNTU-CVE-2026-69247","UBUNTU-CVE-2026-69248","UBUNTU-CVE-2026-69249"],"upstream":["CVE-2023-23931","CVE-2026-69247","CVE-2026-69248","CVE-2026-69249","UBUNTU-CVE-2023-23931","UBUNTU-CVE-2026-69247","UBUNTU-CVE-2026-69248","UBUNTU-CVE-2026-69249"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8776-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-23931"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-69247"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-69248"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-69249"}],"affected":[{"package":{"name":"python-cryptography","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/python-cryptography?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.4-1ubuntu1.4+esm6"}]}],"versions":["1.9-1","2.1.3-3","2.1.4-1","2.1.4-1build1","2.1.4-1build2","2.1.4-1ubuntu1","2.1.4-1ubuntu1.1","2.1.4-1ubuntu1.2","2.1.4-1ubuntu1.3","2.1.4-1ubuntu1.4","2.1.4-1ubuntu1.4+esm1","2.1.4-1ubuntu1.4+esm3"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"python-cryptography","binary_version":"2.1.4-1ubuntu1.4+esm6"},{"binary_name":"python3-cryptography","binary_version":"2.1.4-1ubuntu1.4+esm6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8776-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2023-23931"}]}}},{"package":{"name":"python-cryptography","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/python-cryptography?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"46.0.5-1ubuntu2.2"}]}],"versions":["43.0.0-1ubuntu1","46.0.1-1ubuntu2","46.0.5-1ubuntu1","46.0.5-1ubuntu2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"46.0.5-1ubuntu2.2","binary_name":"python3-cryptography"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:26.04:LTS","cves":[{"severity":[{"score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-69247"},{"id":"CVE-2026-69248","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-69249","severity":[{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8776-1.json"}}],"schema_version":"1.9.0"}