Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39892

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

A flaw was found in the cryptography library. This vulnerability occurs when a non-contiguous buffer is passed to certain application programming interfaces (APIs) that accept Python buffers, such as Hash.update(). A remote attacker could exploit this to cause a buffer overflow, potentially leading to a denial of service.

Отчет

In default configurations Red Hat products isolate service processes from total system access. Should an attacker be able to exploit this vulnerability their impact will be limited to that service account and they will not have access to the broader system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Coreopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Affected
Lightspeed Coreredhat-user-workloads/lightspeed-stackAffected
Migration Toolkit for Applications 8redhat-user-workloads/art-imagesWill not fix
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Not affected
Red Hat AI Inference Serverredhat-user-workloads/rhaiis-cpu-ubi9-3-3Will not fix
Red Hat AI Inference Serverredhat-user-workloads/rhaiis-rocm-ubi9-3-3Affected
Red Hat AI Inference Serverredhat-user-workloads/rhaiis-tpu-ubi9-3-3Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8-operatorNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2456735cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API

EPSS

Процентиль: 47%
0.00652
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

CVSS3: 9.8
nvd
4 месяца назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

CVSS3: 9.8
debian
4 месяца назад

cryptography is a package designed to expose cryptographic primitives ...

github
4 месяца назад

Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs

EPSS

Процентиль: 47%
0.00652
Низкий

7.3 High

CVSS3