​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-f4qg-9fw4-8247

Published

Last updated

https://images.chainguard.dev/security/CGA-f4qg-9fw4-8247
Package

airflow

Latest Update
Pending upstream fix
Aliases
  • CVE-2024-26130
  • GHSA-6vqw-3v5j-54x4

Severity

7.5

High

CVSS V3

Summary

cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override

Description

If pkcs12.serialize_key_and_certificates is called with both:

  1. A certificate whose public key did not match the provided private key
  2. An encryption_algorithm with hmac_hash set (via PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)

Then a NULL pointer dereference would occur, crashing the Python process.

This has been resolved, and now a ValueError is properly raised.

Patched in https://github.com/pyca/cryptography/pull/10423

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images