Your message dated Tue, 04 Aug 2026 21:04:29 +0000
with message-id <[email protected]>
and subject line Bug#1143596: fixed in python-cryptography 49.0.0-2
has caused the Debian Bug report #1143596,
regarding python-cryptography: CVE-2026-69247
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143596: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143596
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-cryptography
Version: 47.0.0-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for python-cryptography.
CVE-2026-69247[0]:
| cryptography is a package designed to expose cryptographic
| primitives and recipes to Python developers. From 44.0.0 until
| 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and
| pkcs7_decrypt_smime reported the outcome of decrypting a
| RecipientInfo's encryptedKey in several distinguishable ways, one of
| which disclosed the exact length recovered from the RSA operation.
| The same distinction was also observable by timing. An application
| that decrypts attacker-supplied EnvelopedData and reflects the
| outcome gives the attacker a Bleichenbacher oracle against the
| content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of
| encryptedKey, build an AES cipher from the result, then AES-CBC
| decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with
| a bad key length, a correct length with a wrong key, and the real
| key each failed or succeeded differently. Case 1 is reachable only
| where the linked library lacks implicit rejection: OpenSSL 3.0 and
| 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that
| auto-decrypts untrusted EnvelopedData matching the victim
| certificate and answers adaptively at high volume, such as an S/MIME
| gateway or mail filter. This issue is fixed in 50.0.0.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-69247
https://www.cve.org/CVERecord?id=CVE-2026-69247
[1] https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5
[2] https://github.com/pyca/cryptography/pull/15369
[3]
https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: python-cryptography
Source-Version: 49.0.0-2
Done: Andrey Rakhmatullin <[email protected]>
We believe that the bug you reported is fixed in the latest version of
python-cryptography, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Andrey Rakhmatullin <[email protected]> (supplier of updated python-cryptography
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 05 Aug 2026 01:32:33 +0500
Source: python-cryptography
Architecture: source
Version: 49.0.0-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>
Changed-By: Andrey Rakhmatullin <[email protected]>
Closes: 1143596
Changes:
python-cryptography (49.0.0-2) unstable; urgency=medium
.
* Backport the upstream fix for CVE-2026-69247 (Closes: #1143596).
Checksums-Sha1:
dcf7bb47041fe08c906d2643efab058706181f43 3345 python-cryptography_49.0.0-2.dsc
5c00c50b1115903b1731d9639cb7f8b1843450b2 14764
python-cryptography_49.0.0-2.debian.tar.xz
2b847ddee5c0d3e72acdc3e1e25abe25f6708802 30434
python-cryptography_49.0.0-2_amd64.buildinfo
Checksums-Sha256:
c0d3243f27a5f8e6f6c87c0858114c979b7a092e821da81515154bba27442756 3345
python-cryptography_49.0.0-2.dsc
d75f5130e362c62133335e8a78d7bf923a25641931d61343219705129026cfbd 14764
python-cryptography_49.0.0-2.debian.tar.xz
515d8f8170a89f823251ca99ffcd2a92373445dcf763e5c5c23eaa71cc8e1444 30434
python-cryptography_49.0.0-2_amd64.buildinfo
Files:
a81a656b49e3b2a30d59390c44a99001 3345 python optional
python-cryptography_49.0.0-2.dsc
e10df89765c6b3e815811c3de55920bd 14764 python optional
python-cryptography_49.0.0-2.debian.tar.xz
7b013aa5fbd8ce748f2b424a22fbc853 30434 python optional
python-cryptography_49.0.0-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtf6ieDcfC1EgtGkao+OWn23e7IYFAmpyTbkACgkQo+OWn23e
7IbpOhAAw6oJQC5l3zR6TwX4queA81SqxQPLXAPcU3OSk0V1KP5sXF/fY+97c9Ie
98AykebKXnN71voKBuSeAlgH1JERB4SR2EGFPQwtdT6xnAFN2/fFzH25UYdSDDy9
AphLYYIUbJVMlsJeGuAOsQ+840chNO/2QkvZ7ySFK0Jb2Q41ccA7LZ1faOXEzdBs
NvpR4riNJMurZDURdzFv+bigIoS7XdNZ10oATcan9apSiCZlVvBgrnQWR2BH51fC
6DBroRJS6KAT06OTgUNSj5Pe4pIbvlzxPy0RBr09wtj2khOvQsJADXBMzeOaToe/
JBUxu9oUKSrYQgdfw8sj+pmAM80zq2SYrJBn5CwkFpEpHnPNK9k5cpVSUMQhUq3i
Uj0WOv/fR5W1EDxZV3StaVeYtPFKh867O5cwn526dM/odK/oeSh9QsAUrC+stJgS
Hyyp9sr3X+UeAJJscmM62dB6YcgbAJc3CEjYHjaBKWGLClqur9jUtbERakG8Sd6w
zoUYijpMFEXQaToiNGOAgcyKIQQ+0ED3+th5Zmo0RhWIg4bxUfda6OLR5eRW6j+A
ei7FZEbYVv8zDSfbuFM/XYqZ4/ABrDBs7tIQl2NUg+XruFsuPQ+CM92aiHZ33GZX
ldaXuz+frzJxSR1NjKZoDAH0T/7YAFYOkN51DC/1PvXDy70jRlY=
=TRXk
-----END PGP SIGNATURE-----
pgpY2Sl429mNu.pgp
Description: PGP signature
--- End Message ---