Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3424-1

Опубликовано: 30 июл. 2026
Источник: suse-cvrf

Описание

Security update for python3-pyOpenSSL

This update for python3-pyOpenSSL fixes the following issue:

  • CVE-2026-27448: unhandled exception in set_tlsext_servername_callback callback can result in connection not being cancelled and allows for possible security measure bypassing (bsc#1259804).

Список пакетов

Container suse/manager/4.3/proxy-httpd:latest
python3-pyOpenSSL-21.0.0-150400.22.1
Container suse/manager/4.3/proxy-tftpd:latest
python3-pyOpenSSL-21.0.0-150400.22.1
SUSE Linux Enterprise Micro 5.3
python3-pyOpenSSL-21.0.0-150400.22.1
SUSE Linux Enterprise Micro 5.4
python3-pyOpenSSL-21.0.0-150400.22.1
SUSE Linux Enterprise Micro 5.5
python3-pyOpenSSL-21.0.0-150400.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
python3-pyOpenSSL-21.0.0-150400.22.1

Описание

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.


Затронутые продукты
Container suse/manager/4.3/proxy-httpd:latest:python3-pyOpenSSL-21.0.0-150400.22.1
Container suse/manager/4.3/proxy-tftpd:latest:python3-pyOpenSSL-21.0.0-150400.22.1
SUSE Linux Enterprise Micro 5.3:python3-pyOpenSSL-21.0.0-150400.22.1
SUSE Linux Enterprise Micro 5.4:python3-pyOpenSSL-21.0.0-150400.22.1

Ссылки