Wind River Support Network

HomeDefectsLIN1019-11001
Fixed

LIN1019-11001 : Security Advisory - python-cryptography - CVE-2024-26130

Created: Feb 21, 2024    Updated: Feb 27, 2024
Resolved Date: Feb 27, 2024
Found In Version: 10.19.45.1
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Userspace

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.

CREATE(Triage):(User=admin) CVE-2024-26130 (https://nvd.nist.gov/vuln/detail/CVE-2024-26130)
Live chat
Online