[ubuntu/resolute-security] python-cryptography 46.0.5-1ubuntu2.2 (Accepted)

Hlib Korzhynskyy hlib.korzhynskyy at canonical.com
Wed Sep 16 16:16:25 UTC 2026


python-cryptography (46.0.5-1ubuntu2.2) resolute-security; urgency=medium

  * SECURITY UPDATE: sensitive decryption data is leaked
    - debian/patches/CVE-2026-69247.patch: don't leak how PKCS#7 encryptedKey
      decryption failed in docs/hazmat/primitives/asymmetric/serialization.rst,
      docs/spelling_wordlist.txt, src/rust/src/pkcs7.rs, tests/doubles.py,
      tests/hazmat/primitives/test_pkcs7.py.
    - CVE-2026-69247
  * SECURITY UPDATE: acceptance of non-permitted DNS names
    - debian/patches/CVE-2026-69248.patch: distinguish NC kinds when
      evaluating wildcard DNS SANs in
      src/rust/cryptography-x509-verification/src/lib.rs,
      src/rust/cryptography-x509-verification/src/types.rs.
    - CVE-2026-69248
  * SECURITY UPDATE: exponential processing of invalid certificates
    - debian/patches/CVE-2026-69249.patch: add a signature validation budget
      during path construction in
      src/rust/cryptography-x509-verification/src/lib.rs,
      src/rust/cryptography-x509-verification/src/policy/mod.rs.
    - CVE-2026-69249

Date: 2026-09-15 18:31:12.354600+00:00
Changed-By: Charles Cochran <charles.cochran at canonical.com>
Signed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/python-cryptography/46.0.5-1ubuntu2.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list