SUSE-SU-2026:23404-1
Advisory lineage Upstream: 3 Downstream: 0
Published: 30 Aug 2026, 14:38
Last modified:10 Sept 2026, 18:23
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
30 Aug 2026, 14:38
Published
Vulnerability first disclosed
10 Sept 2026, 18:23
Last Modified
Vulnerability information updated
Description
Security update for python-cryptography This update for python-cryptography fixes the following issues: - CVE-2026-69247: PKCS#7 `EnvelopedData` decryption exposes a Bleichenbacher oracle through distinguishable errors and timing (bsc#1273551). - CVE-2026-69248: verifier accepts wildcard DNS names allowing escape from `permittedSubtrees` (bsc#1273549). - CVE-2026-69249: duplicate self-signed intermediates can cause exponential path-building (bsc#1273516).
Affected Systems
- suse•python-cryptography&distro=SUSE Linux Micro 6.2
< 44.0.3-160000.5.1
References (7)
- https://www.suse.com/support/update/announcement/2026/suse-su-202623404-1/
- https://bugzilla.suse.com/1273516
- https://bugzilla.suse.com/1273549
- https://bugzilla.suse.com/1273551
- https://www.suse.com/security/cve/CVE-2026-69247
- https://www.suse.com/security/cve/CVE-2026-69248
- https://www.suse.com/security/cve/CVE-2026-69249