Описание
Security update for python-pyOpenSSL
This update for python-pyOpenSSL fixes the following issue:
- CVE-2026-27448: unhandled exception can result in connection not being cancelled (bsc#1259804).
Список пакетов
Image SLES12-SP5-Azure-BYOS
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-Azure-HPC-BYOS
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-Azure-HPC-On-Demand
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-Azure-SAP-BYOS
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-Azure-SAP-On-Demand
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-Azure-Standard-On-Demand
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-EC2-BYOS
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-EC2-ECS-On-Demand
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-EC2-On-Demand
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-EC2-SAP-BYOS
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-EC2-SAP-On-Demand
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-GCE-BYOS
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-GCE-On-Demand
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-GCE-SAP-BYOS
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-GCE-SAP-On-Demand
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
python-pyOpenSSL-17.1.0-4.32.1
python3-pyOpenSSL-17.1.0-4.32.1
Ссылки
- Link for SUSE-SU-2026:1582-1
- E-Mail link for SUSE-SU-2026:1582-1
- SUSE Security Ratings
- SUSE Bug 1259804
- SUSE CVE CVE-2026-27448 page
Описание
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.
Затронутые продукты
Image SLES12-SP5-Azure-BYOS:python-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-Azure-BYOS:python3-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-Azure-HPC-BYOS:python-pyOpenSSL-17.1.0-4.32.1
Image SLES12-SP5-Azure-HPC-BYOS:python3-pyOpenSSL-17.1.0-4.32.1
Ссылки
- CVE-2026-27448
- SUSE Bug 1259804