Aggregator

xen-4.21.2-2.fc44

4 days 14 hours ago
FEDORA-2026-1d448c1d40 Packages in this update:
  • xen-4.21.2-2.fc44
Update description:

x86: DMs may cause mem leak by IRQ binding [XSA-509, CVE-2026-62437] x86: improper handling of HVM emulation return codes [XSA-510, CVE-2026-79602] Unconditionally do TLB flushing ahead of page scrubbing [XSA-511, CVE-2026-79603] oxenstored: Unbounded accumulation of watches [XSA-512, CVE-2026-79604]

USN-8776-1: python-cryptography vulnerabilities

4 days 15 hours ago
It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectations. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-23931) It was discovered that python-cryptography reported the outcome of decrypting PKCS#7 enveloped data in distinguishable ways, and with observable timing differences. A remote attacker could possibly use this issue to recover the key used to encrypt the message contents, and obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69247) Jack Lloyd discovered that python-cryptography incorrectly handled wildcard DNS names when enforcing the name constraints of a certificate authority. A remote attacker could possibly use this issue to have an invalid certificate chain accepted, and use names outside of the permitted ones. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248) Samuel Judson discovered that python-cryptography incorrectly handled certificate chains that contained duplicate certificates. A remote attacker could possibly use this issue to cause python-cryptography to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69249)