cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat rhui
|
|
CPEs | cpe:/a:redhat:rhui:4::el8 | |
Vendors & Products |
Redhat rhui
|
Wed, 05 Feb 2025 22:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cryptography.io
Cryptography.io cryptography |
|
CPEs | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* | |
Vendors & Products |
Cryptography.io
Cryptography.io cryptography |
Fri, 11 Oct 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat satellite
Redhat satellite Capsule |
|
CPEs | cpe:/a:redhat:satellite:6.15::el8 cpe:/a:redhat:satellite_capsule:6.15::el8 |
|
Vendors & Products |
Redhat satellite
Redhat satellite Capsule |

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-14T20:01:52.628Z
Reserved: 2024-02-14T17:40:03.687Z
Link: CVE-2024-26130

Updated: 2024-08-01T23:59:32.542Z

Status : Analyzed
Published: 2024-02-21T17:15:09.863
Modified: 2025-02-05T22:09:20.427
Link: CVE-2024-26130
