python3.12-cryptography-41.0.7-2.el9_6.1
エラータID: AXSA:2025-10844:02
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.
Security Fix(es):
* python-cryptography: NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override (CVE-2024-26130)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2024-26130
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.
Update packages.
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.
N/A
SRPMS
- python3.12-cryptography-41.0.7-2.el9_6.1.src.rpm
MD5: 2452cd62c5493ffab42eed5e4033e381
SHA-256: a4c5c6a2cd0c4b1f37a9205c36bfe59fa9822ba1e45769b083b05b8df1593487
Size: 41.81 MB
Asianux Server 9 for x86_64
- python3.12-cryptography-41.0.7-2.el9_6.1.x86_64.rpm
MD5: 87475938c565e2e9b5ccc45f89a2d065
SHA-256: 94e2d366c977c27c9a6891c4b4b112aab8133bfe6666f09883e2ba6bbde3df5f
Size: 1.23 MB