Security Advisory Desk
unratedQCS priority 76/100Ubuntu

USN-8776-1: python-cryptography vulnerabilities

Several security vulnerabilities were found in the python-cryptography library on Ubuntu systems. These issues could cause corrupted outputs, expose encryption keys, allow invalid certificates to be accepted, or cause denial of service due to excessive resource use. They affect Ubuntu 18.04 LTS and 26.04 LTS users differently and require system updates to resolve.

Published 16/9/2026, 8:12:52 pmVerified 18/9/2026, 6:33:31 amRevision 1
Ubuntu unrated network security advisory visual

In plain language

What this advisory means

Several security vulnerabilities were found in the python-cryptography library on Ubuntu systems. These issues could cause corrupted outputs, expose encryption keys, allow invalid certificates to be accepted, or cause denial of service due to excessive resource use. They affect Ubuntu 18.04 LTS and 26.04 LTS users differently and require system updates to resolve.

Technical explanation

How the issue affects the environment

Four distinct vulnerabilities were identified in python-cryptography. CVE-2023-23931 affects Ubuntu 18.04 LTS and involves accepting immutable buffer objects in cipher operations, producing corrupted outputs. CVE-2026-69247 affects Ubuntu 26.04 LTS, where PKCS#7 decryption outcomes vary in a distinguishable manner and timing, potentially allowing attackers to extract encryption keys. CVE-2026-69248 involves improper handling of wildcard DNS names in certificate authority name constraints, which could let attackers forge certificate chains. CVE-2026-69249 concerns resource exhaustion caused by duplicate certificates in chains, risking denial of service. Updates are provided to address these issues.

Operational impact

Why teams should care

Exploitation could lead to data corruption, sensitive data exposure through key recovery, improper trust of invalid certificates, and service disruptions from denial-of-service attacks. This threatens confidentiality, integrity, and availability of services relying on python-cryptography on Ubuntu systems.

Immediate action

Users should update their python-cryptography packages to the fixed versions provided by Ubuntu through standard system updates or via Ubuntu Pro for extended security maintenance.

Affected and fixed releases

Affected versionsUbuntu 18.04 LTS python-cryptography versions prior to 2.1.4-1ubuntu1.4+esm6, Ubuntu 26.04 LTS python-cryptography versions prior to 46.0.5-1ubuntu2.2
Fixed versionsUbuntu 18.04 LTS python-cryptography 2.1.4-1ubuntu1.4+esm6, Ubuntu 26.04 LTS python-cryptography 46.0.5-1ubuntu2.2

Temporary risk reduction

The official source does not specify any workarounds. Applying updates is the recommended resolution.

Evidence and validation checklist

  • Ubuntu Security Notice USN-8776-1
  • CVE listings CVE-2023-23931, CVE-2026-69247, CVE-2026-69248, CVE-2026-69249
  • Updated package versions provided by Ubuntu
  • Security analysis by Jack Lloyd and Samuel Judson

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
USN-8776-1: python-cryptography vulnerabilities | Advisory | QCS