Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20419-1

Опубликовано: 25 мар. 2026
Источник: suse-cvrf

Описание

Security update for python-pyOpenSSL

This update for python-pyOpenSSL fixes the following issues:

  • CVE-2026-27448: unhandled exception can result in connection not being cancelled (bsc#1259804).
  • CVE-2026-27459: large cookie value can lead to a buffer overflow (bsc#1259808).

Список пакетов

openSUSE Leap 16.0
python313-pyOpenSSL-25.0.0-160000.3.1

Описание

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.


Затронутые продукты
openSUSE Leap 16.0:python313-pyOpenSSL-25.0.0-160000.3.1

Ссылки

Описание

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.


Затронутые продукты
openSUSE Leap 16.0:python313-pyOpenSSL-25.0.0-160000.3.1

Ссылки