Multiple Vulnerabilities in Red Hat Enterprise Linux python-cryptography Package
Multiple vulnerabilities in the python-cryptography package for Red Hat Enterprise Linux, including CVE-2024-26130, may allow a remote, unauthenticated attacker to bypass security controls or cause a denial-of-service condition.
CVE search metadata
CVE search record: CVE-2024-26130. Severity: high. CVSS: 7.5. EPSS: 0.83%. KEV: no. Product: Enterprise Linux (python-cryptography), Enterprise Linux. Brief: Multiple Vulnerabilities in Red Hat Enterprise Linux python-cryptography Package. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rhel-python-cryptography/
What's new
- 1. added coverage for Enterprise Linux Sep 11, 12:54 via bsi
The python-cryptography library included in Red Hat Enterprise Linux (RHEL) is affected by multiple security vulnerabilities, most notably CVE-2024-26130. These flaws stem from improper handling of specific cryptographic operations within the library. A remote, unauthenticated attacker could leverage these weaknesses to bypass security restrictions or trigger a denial-of-service (DoS) condition, potentially leading to application crashes or the compromise of integrity in services relying on affected cryptographic functions. Defenders should prioritize updating the python-cryptography package across all RHEL distributions, as it is a foundational library for many Python-based services and management utilities.
Impact
Successful exploitation could lead to a denial-of-service, rendering impacted services unavailable, or the subversion of cryptographic protections intended to secure data in transit or at rest. All RHEL environments utilizing the affected library are at risk.
Recommendation
Prioritize the identification and patching of systems running the affected python-cryptography versions. Use package management tools to audit installed versions and ensure the latest security updates provided by Red Hat are applied.
Mitigations
Update python-cryptography via the Red Hat package manager (yum or dnf) to the latest secure version.
CVE-2024-26130