CVE-2026-39892

Name
CVE-2026-39892
Description
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2026/04/08/12
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19375
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:20338
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:21017
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:22465
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:22629
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:22840
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:23361
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:24483
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:24761
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:24762
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:24853
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:24866
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:24977
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:30088
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:30089
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:7295
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/security/cve/CVE-2026-39892
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://bugzilla.redhat.com/show_bug.cgi?id=2456735
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39892.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:37275
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:42644
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:43651
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:43670
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:43851
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:43853
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:43854
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:43855
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:46956

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* py3-cryptography >= 45.0.0 < 46.0.7

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-cryptography edge-main 46.0.7-r0 Duncan Bellamy <dunk@denkimushi.com> fixed
py3-cryptography edge-main 46.0.5-r1 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
py3-cryptography edge-main 46.0.5-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
py3-cryptography edge-main 46.0.3-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
py3-cryptography edge-main 46.0.2-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
py3-cryptography 3.23-main 46.0.7-r0 Duncan Bellamy <dunk@denkimushi.com> fixed
py3-cryptography 3.23-main 46.0.5-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
py3-cryptography 3.23-main 46.0.3-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable