[ubuntu/questing-updates] pyopenssl 25.0.0-1ubuntu0.1 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Mon Mar 23 14:29:35 UTC 2026


pyopenssl (25.0.0-1ubuntu0.1) questing-security; urgency=medium

  * SECURITY UPDATE: Unhandled exceptions in set_tlsext_servername_callback
    - debian/patches/CVE-2026-27448.patch: handle exceptions in callbacks
      in src/OpenSSL/SSL.py, tests/test_ssl.py.
    - CVE-2026-27448
  * SECURITY UPDATE: Buffer overflow via DTLS cookie callback
    - debian/patches/CVE-2026-27459.patch: fix buffer overflow in DTLS
      cookie generation callback in src/OpenSSL/SSL.py, tests/test_ssl.py.
    - CVE-2026-27459

Date: 2026-03-18 17:52:10.502877+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/pyopenssl/25.0.0-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list