USN-8776-1: python-cryptography vulnerabilities

Publication date

16 September 2026

Overview

Several security issues were fixed in python-cryptography.


Packages

Details

It was discovered that python-cryptography incorrectly accepted objects
with immutable buffers when performing certain cipher operations. This
would result in corrupted output, contrary to expectations. This issue only
affected Ubuntu 18.04 LTS. (CVE-2023-23931)

It was discovered that python-cryptography reported the outcome of
decrypting PKCS#7 enveloped data in distinguishable ways, and with
observable timing differences. A remote attacker could possibly use this
issue to recover the key used to encrypt the message contents, and obtain
sensitive information. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-69247)

Jack Lloyd discovered that python-cryptography incorrectly handled wildcard
DNS names when enforcing the name constraints of a certificate authority. A
remote attacker could possibly use this issue to have an invalid
certificate...

It was discovered that python-cryptography incorrectly accepted objects
with immutable buffers when performing certain cipher operations. This
would result in corrupted output, contrary to expectations. This issue only
affected Ubuntu 18.04 LTS. (CVE-2023-23931)

It was discovered that python-cryptography reported the outcome of
decrypting PKCS#7 enveloped data in distinguishable ways, and with
observable timing differences. A remote attacker could possibly use this
issue to recover the key used to encrypt the message contents, and obtain
sensitive information. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-69247)

Jack Lloyd discovered that python-cryptography incorrectly handled wildcard
DNS names when enforcing the name constraints of a certificate authority. A
remote attacker could possibly use this issue to have an invalid
certificate chain accepted, and use names outside of the permitted ones.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248)

Samuel Judson discovered that python-cryptography incorrectly handled
certificate chains that contained duplicate certificates. A remote attacker
could possibly use this issue to cause python-cryptography to use excessive
resources, leading to a denial of service. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-69249)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute python-cryptography-doc –  46.0.5-1ubuntu2.2
python3-cryptography –  46.0.5-1ubuntu2.2
18.04 LTS bionic python-cryptography –  2.1.4-1ubuntu1.4+esm6  
python-cryptography-doc –  2.1.4-1ubuntu1.4+esm6  
python3-cryptography –  2.1.4-1ubuntu1.4+esm6  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›