python3.12-cryptography-41.0.7-2.el9

エラータID: AXSA:2025-10071:01

Release date: 
Friday, June 27, 2025 - 18:08
Subject: 
python3.12-cryptography-41.0.7-2.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

* rust-openssl: rust openssl ssl::select_next_proto use after free (CVE-2025-24898)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the MIRACLE LINUX 9 Release Notes linked from the References section.

CVE-2025-24898
rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_proto` can return a slice pointing into the `server` argument's buffer but with a lifetime bound to the `client` argument. In situations where the `sever` buffer's lifetime is shorter than the `client` buffer's, this can cause a use after free. This could cause the server to crash or to return arbitrary memory contents to the client. The crate`openssl` version 0.10.70 fixes the signature of `ssl::select_next_proto` to properly constrain the output buffer's lifetime to that of both input buffers. Users are advised to upgrade. In standard usage of `ssl::select_next_proto` in the callback passed to `SslContextBuilder::set_alpn_select_callback`, code is only affected if the `server` buffer is constructed *within* the callback.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python3.12-cryptography-41.0.7-2.el9.src.rpm
    MD5: 26d2fbe58a6e9e7d99a2348ca73cae65
    SHA-256: 048f5ae994290ae04e02a838636eec0bda14aaccfaa10e1cda849cc5550891d9
    Size: 41.81 MB

Asianux Server 9 for x86_64
  1. python3.12-cryptography-41.0.7-2.el9.x86_64.rpm
    MD5: 3160f8d1886d7a367c11f62886298186
    SHA-256: 530336eec7dc151b4f096d0374d9fb3d0cd5228e3ea31efab6b9230b0433c483
    Size: 1.23 MB