CVE-2024-26130

Aliases:GHSA-6vqw-3v5j-54x4PYSEC-2024-225DEBIAN-CVE-2024-26130CGA-2gpw-7gxw-5q2qCGA-2xx9-mj62-fcp9CGA-4622-8x7f-p986CGA-4mgp-7v94-77r9CGA-5pw5-8gm7-j4pjCGA-5vrj-4w5g-2v8hCGA-6crm-j9xh-263qCGA-6pw7-4w75-66crCGA-6v5w-gx3q-c92vCGA-82vf-5839-wcv5CGA-9wjj-c2r8-q4g2CGA-f7v7-56q3-fp34CGA-f8g8-64vm-chr9CGA-fvfj-m226-r2jvCGA-g5fg-f8g3-6j42CGA-hjw5-p394-wxm4CGA-jf23-6x48-wcpmCGA-266w-66rw-qq6wCGA-qwf8-c766-mp37CGA-v73g-hj64-x522CGA-vr9g-f73r-792cCGA-wvjp-fwqv-mx56CGA-x4mw-38jr-4q5vCGA-xpqx-5jmw-g35q
Analyzed
Published: 21 Feb 2024, 16:28
Last modified:14 Aug 2024, 20:01

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.83% LOW
1% probability +0.49%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Feb 2024, 16:28
Published
Vulnerability first disclosed
14 Aug 2024, 20:01
Last Modified
Vulnerability information updated

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.83% Percentile: 56%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • chainguardairflow

    all | < 2.10.5-r44

  • chainguardairflow-bitnami-compat

    all

  • chainguardaz

    < 2.58.0-r0

  • chainguardaz-iamguarded-compat

    < 2.58.0-r0

  • chainguardggshield

    < 1.25.0-r0

  • chainguardkubeflow-pipelines

    < 2.0.5-r3

  • chainguardmitmproxy

    < 12.2.1-r0

  • chainguardpy3-cassandra-medusa

    < 0.19.1-r1

  • chainguardpy3-cassandra-medusa-compat

    < 0.19.1-r1

  • chainguardpy3-cryptography

    < 42.0.4-r0

  • chainguardrequest-1276

    < 0.23.0-r30

  • chainguardrequest-1276-compat

    < 0.23.0-r30

  • wolfiairflow

    all | < 2.10.5-r44

  • wolfiairflow-bitnami-compat

    all

  • wolfiaz

    < 2.58.0-r0

  • wolfiaz-iamguarded-compat

    < 2.58.0-r0

  • wolfiggshield

    < 1.25.0-r0

  • wolfikubeflow-pipelines

    < 2.0.5-r3

  • wolfimitmproxy

    < 12.2.1-r0

  • wolfipy3-cassandra-medusa

    < 0.19.1-r1

  • wolfipy3-cassandra-medusa-compat

    < 0.19.1-r1

  • wolfipy3-cryptography

    < 42.0.4-r0

  • cryptography.iocryptography

    ≥ 38.0.0, < 42.0.4

  • debianpython-cryptography

    < 38.0.4-3+deb12u1 | < 42.0.5-1 | < 42.0.5-1

  • pycacryptography

    ≥ 38.0.0, < 42.0.4

  • PyPIcryptography

    < 97d231672763cdb5959a3b191e692a362f1b9e55 | ≥ 38.0.0, < 42.0.4

References (9)