NA

CVE-2024-26130

Published: 21/02/2024 Updated: 22/02/2024

Vulnerability Summary

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1064778 python-cryptography: CVE-2024-26130 Package: src:python-cryptography; Maintainer for src:python-cryptography is Debian Python Team <team+python@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 25 Feb 2024 20:03:01 UTC Severity: important Tags: sec ...