SUSE-SU-2026:23404-1

Advisory lineage Upstream: 3 Downstream: 0
Published: 30 Aug 2026, 14:38
Last modified:10 Sept 2026, 18:23

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Aug 2026, 14:38
Published
Vulnerability first disclosed
10 Sept 2026, 18:23
Last Modified
Vulnerability information updated

Description

Security update for python-cryptography This update for python-cryptography fixes the following issues: - CVE-2026-69247: PKCS#7 `EnvelopedData` decryption exposes a Bleichenbacher oracle through distinguishable errors and timing (bsc#1273551). - CVE-2026-69248: verifier accepts wildcard DNS names allowing escape from `permittedSubtrees` (bsc#1273549). - CVE-2026-69249: duplicate self-signed intermediates can cause exponential path-building (bsc#1273516).

Affected Systems

  • susepython-cryptography&distro=SUSE Linux Micro 6.2

    < 44.0.3-160000.5.1

References (7)