cryptography has a buffer overflow if non-contiguous buffers were passed to APIs
Summary
| CVE | CVE-2026-39892 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-08 21:17:01 UTC |
| Updated | 2026-08-17 12:18:23 UTC |
| Description | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. |
Risk And Classification
Primary CVSS: v4.0 6.9 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.006520000 probability, percentile 0.482640000 (date 2026-08-17)
Problem Types: CWE-119 | CWE-131 | CWE-119 CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer | CWE-131 Incorrect Calculation of Buffer Size
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6.9 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 6.9 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | CVSS | 7.3 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.3 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cryptography.io | Cryptography | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Pyca | Cryptography | affected >= 45.0.0, < 46.0.7 | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.5 For RHEL 8 | unaffected 0:4.6.29-2.el8ap * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.5 For RHEL 8 | unaffected 0:46.0.7-1.el8ap * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.5 For RHEL 9 | unaffected 0:4.6.29-2.el9ap * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.5 For RHEL 9 | unaffected 0:46.0.7-1.el9ap * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.6 For RHEL 9 | unaffected 0:4.7.12-1.el9ap * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.6 For RHEL 9 | unaffected 0:46.0.7-1.el9ap * rpm | Not specified |
| ADP | Red Hat | Red Hat AI Inference Server 3.3 | unaffected 1782353093 * rpm | Not specified |
| ADP | Red Hat | Red Hat AI Inference Server 3.3 | unaffected 1782352847 * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.6 | unaffected 1779762270 * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.6 | unaffected 1779759716 * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.6 | unaffected 1779734628 * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.6 | unaffected 1779773804 * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.6 | unaffected 1779761061 * rpm | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2.6 | unaffected 1779760844 * rpm | Not specified |
| ADP | Red Hat | Red Hat Discovery 2 | unaffected 1779395228 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux AI 3.3 | unaffected 1784670204 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux AI 3.3 | unaffected 1784669680 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux AI 3.3 | unaffected 1784736822 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux AI 3.3 | unaffected 1784736941 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux AI 3.3 | unaffected 1784736798 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux AI 3.3 | unaffected 1784736857 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux AI 3.3 | unaffected 1785163184 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 46.0.7-1.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 2.25 | unaffected 1780069069 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 2.25 | unaffected 1783701598 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.3 | unaffected 1782471587 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.3 | unaffected 1782472374 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.3 | unaffected 1782471606 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.1 | unaffected 1779822261 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.12 | unaffected 1779811412 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.14 | unaffected 1779689392 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.15 | unaffected 1780891395 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.16 | unaffected 1779204086 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.17 | unaffected 1779922205 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.9 | unaffected 1779811473 * rpm | Not specified |
| ADP | Red Hat | Red Hat Trusted Artifact Signer 1.4 | unaffected 1780914886 * rpm | Not specified |
| ADP | Red Hat | Lightspeed Core | Not specified | Not specified |
| ADP | Red Hat | Lightspeed Core | Not specified | Not specified |
| ADP | Red Hat | Migration Toolkit For Applications 8 | Not specified | Not specified |
| ADP | Red Hat | OpenShift Lightspeed | Not specified | Not specified |
| ADP | Red Hat | OpenShift Lightspeed | Not specified | Not specified |
| ADP | Red Hat | Red Hat AI Inference Server | Not specified | Not specified |
| ADP | Red Hat | Red Hat AI Inference Server | Not specified | Not specified |
| ADP | Red Hat | Red Hat AI Inference Server | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform Ansible Core 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform Ansible Core 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform Ansible Core 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Ansible Automation Platform Ansible Core 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux AI RHEL AI 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux AI RHEL AI 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux AI RHEL AI 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Satellite 6 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Satellite 6 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Satellite 6 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Satellite 6 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2026:7295 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:43670 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:24853 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:43853 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:20338 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:24977 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| www.openwall.com/lists/oss-security/2026/04/08/12 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Release Notes, Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:22629 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:42644 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-39892 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:43851 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:43854 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:21017 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:43651 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:24762 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:37275 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:30089 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:24483 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:19375 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:43855 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:22465 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:46956 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:30088 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:24866 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:23361 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq | [email protected] | github.com | Vendor Advisory |
| access.redhat.com/errata/RHSA-2026:24761 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:22840 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39892.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-04-08T22:00:59.416Z | Reported to Red Hat. |
| ADP | 2026-04-08T20:49:41.967Z | Made public. |
Solutions
ADP: RHSA-2026:24761: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9
ADP: RHSA-2026:24762: Red Hat Ansible Automation Platform 2.6 for RHEL 9
ADP: RHSA-2026:30089: Red Hat AI Inference Server 3.3
ADP: RHSA-2026:30088: Red Hat AI Inference Server 3.3
ADP: RHSA-2026:24866: Red Hat Ansible Automation Platform 2.6
ADP: RHSA-2026:20338: Red Hat Discovery 2
ADP: RHSA-2026:43855: Red Hat Enterprise Linux AI 3.3
ADP: RHSA-2026:43854: Red Hat Enterprise Linux AI 3.3
ADP: RHSA-2026:43851: Red Hat Enterprise Linux AI 3.3
ADP: RHSA-2026:43670: Red Hat Enterprise Linux AI 3.3
ADP: RHSA-2026:43853: Red Hat Enterprise Linux AI 3.3
ADP: RHSA-2026:43651: Red Hat Enterprise Linux AI 3.3
ADP: RHSA-2026:46956: Red Hat Enterprise Linux AI 3.3
ADP: RHSA-2026:7295: Red Hat Hardened Images
ADP: RHSA-2026:42644: Red Hat OpenShift AI 2.25
ADP: RHSA-2026:24977: Red Hat OpenShift AI 2.25
ADP: RHSA-2026:37275: Red Hat OpenShift AI 3.3
ADP: RHSA-2026:22629: Red Hat Quay 3.12
ADP: RHSA-2026:21017: Red Hat Quay 3.14
ADP: RHSA-2026:24853: Red Hat Quay 3.15
ADP: RHSA-2026:19375: Red Hat Quay 3.16
ADP: RHSA-2026:22465: Red Hat Quay 3.17
ADP: RHSA-2026:22840: Red Hat Quay 3.1
ADP: RHSA-2026:23361: Red Hat Quay 3.9
ADP: RHSA-2026:24483: Red Hat Trusted Artifact Signer 1.4
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.