{"id":"openSUSE-SU-2026:20650-1","summary":"Security update for python-PyNaCl","details":"This update for python-PyNaCl fixes the following issues:\n\nSecurity fixes:\n\n- CVE-2025-69277: incorrect validation of elliptic curve points certain custom cryptography or untrusted data to\n  crypto_core_ed25519_is_valid_point function (bsc#1255764).\n\nOther fixes:\n\n- update to 1.6.2 (bsc#1255764, CVE-2025-69277):\n * Updated libsodium to 1.0.20-stable (2025-12-31 build)\n- Update to 1.6.1\n * The ``MAKE`` environment variable can now be used to specify\n the ``make`` binary that should be used in the build process.\n- update to 1.6.0:\n * BACKWARDS INCOMPATIBLE: Removed support for Python 3.6 and\n 3.7.\n * Added support for the low level AEAD AES bindings.\n * Added support for crypto_core_ed25519_from_uniform.\n * Update libsodium to 1.0.20-stable (2025-08-27 build).\n * Added support for free-threaded Python 3.14.\n * Added support for Windows on ARM wheels.\n- Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)\n- python-PyNaCl requires python-cffi [bsc#1161557]\n","modified":"2026-05-01T18:29:50.634220Z","published":"2026-04-29T14:17:40Z","related":["CVE-2025-69277"],"upstream":["CVE-2025-69277"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1161557"},{"type":"REPORT","url":"https://bugzilla.suse.com/1199282"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255764"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-69277"}],"schema_version":"1.7.5"}