In plain language
What this advisory means
Several security vulnerabilities were found in the python-cryptography library on Ubuntu systems. These issues could cause corrupted outputs, expose encryption keys, allow invalid certificates to be accepted, or cause denial of service due to excessive resource use. They affect Ubuntu 18.04 LTS and 26.04 LTS users differently and require system updates to resolve.
Technical explanation
How the issue affects the environment
Four distinct vulnerabilities were identified in python-cryptography. CVE-2023-23931 affects Ubuntu 18.04 LTS and involves accepting immutable buffer objects in cipher operations, producing corrupted outputs. CVE-2026-69247 affects Ubuntu 26.04 LTS, where PKCS#7 decryption outcomes vary in a distinguishable manner and timing, potentially allowing attackers to extract encryption keys. CVE-2026-69248 involves improper handling of wildcard DNS names in certificate authority name constraints, which could let attackers forge certificate chains. CVE-2026-69249 concerns resource exhaustion caused by duplicate certificates in chains, risking denial of service. Updates are provided to address these issues.
Operational impact
Why teams should care
Exploitation could lead to data corruption, sensitive data exposure through key recovery, improper trust of invalid certificates, and service disruptions from denial-of-service attacks. This threatens confidentiality, integrity, and availability of services relying on python-cryptography on Ubuntu systems.
Immediate action
Users should update their python-cryptography packages to the fixed versions provided by Ubuntu through standard system updates or via Ubuntu Pro for extended security maintenance.
Affected and fixed releases
Temporary risk reduction
The official source does not specify any workarounds. Applying updates is the recommended resolution.
Evidence and validation checklist
- Ubuntu Security Notice USN-8776-1
- CVE listings CVE-2023-23931, CVE-2026-69247, CVE-2026-69248, CVE-2026-69249
- Updated package versions provided by Ubuntu
- Security analysis by Jack Lloyd and Samuel Judson
Authoritative reference
Ubuntu Security Notices
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
