USN-8776-1

Source
https://ubuntu.com/security/notices/USN-8776-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8776-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8776-1
Upstream
Published
2026-09-16T20:12:52Z
Modified
2026-09-17T02:57:29Z
Summary
python-cryptography vulnerabilities
Details

It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectations. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-23931)

It was discovered that python-cryptography reported the outcome of decrypting PKCS#7 enveloped data in distinguishable ways, and with observable timing differences. A remote attacker could possibly use this issue to recover the key used to encrypt the message contents, and obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69247)

Jack Lloyd discovered that python-cryptography incorrectly handled wildcard DNS names when enforcing the name constraints of a certificate authority. A remote attacker could possibly use this issue to have an invalid certificate chain accepted, and use names outside of the permitted ones. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248)

Samuel Judson discovered that python-cryptography incorrectly handled certificate chains that contained duplicate certificates. A remote attacker could possibly use this issue to cause python-cryptography to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69249)

References

Affected packages

Ubuntu:Pro:18.04:LTS / python-cryptography

Package

Name
python-cryptography
Purl
pkg:deb/ubuntu/python-cryptography?arch=source&distro=esm-infra%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.4-1ubuntu1.4+esm6

Affected versions

1.*
1.9-1
2.*
2.1.3-3
2.1.4-1
2.1.4-1build1
2.1.4-1build2
2.1.4-1ubuntu1
2.1.4-1ubuntu1.1
2.1.4-1ubuntu1.2
2.1.4-1ubuntu1.3
2.1.4-1ubuntu1.4
2.1.4-1ubuntu1.4+esm1
2.1.4-1ubuntu1.4+esm3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "python-cryptography",
            "binary_version": "2.1.4-1ubuntu1.4+esm6"
        },
        {
            "binary_name": "python3-cryptography",
            "binary_version": "2.1.4-1ubuntu1.4+esm6"
        }
    ]
}

Database specific

cves_map
{
    "cves": [],
    "ecosystem": "Ubuntu:Pro:18.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8776-1.json"

Ubuntu:26.04:LTS / python-cryptography

Package

Name
python-cryptography
Purl
pkg:deb/ubuntu/python-cryptography?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
46.0.5-1ubuntu2.2

Affected versions

43.*
43.0.0-1ubuntu1
46.*
46.0.1-1ubuntu2
46.0.5-1ubuntu1
46.0.5-1ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "python3-cryptography",
            "binary_version": "46.0.5-1ubuntu2.2"
        }
    ]
}

Database specific

cves_map
{
    "cves": [],
    "ecosystem": "Ubuntu:26.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8776-1.json"