Skip to content
Threat Feed
low advisory updated

Multiple Vulnerabilities in Red Hat Enterprise Linux python-cryptography Package

Multiple vulnerabilities in the python-cryptography package for Red Hat Enterprise Linux, including CVE-2024-26130, may allow a remote, unauthenticated attacker to bypass security controls or cause a denial-of-service condition.

CVE search metadata

CVE search record: CVE-2024-26130. Severity: high. CVSS: 7.5. EPSS: 0.83%. KEV: no. Product: Enterprise Linux (python-cryptography), Enterprise Linux. Brief: Multiple Vulnerabilities in Red Hat Enterprise Linux python-cryptography Package. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rhel-python-cryptography/

What's new

  • 1. added coverage for Enterprise Linux Sep 11, 12:54 via bsi

The python-cryptography library included in Red Hat Enterprise Linux (RHEL) is affected by multiple security vulnerabilities, most notably CVE-2024-26130. These flaws stem from improper handling of specific cryptographic operations within the library. A remote, unauthenticated attacker could leverage these weaknesses to bypass security restrictions or trigger a denial-of-service (DoS) condition, potentially leading to application crashes or the compromise of integrity in services relying on affected cryptographic functions. Defenders should prioritize updating the python-cryptography package across all RHEL distributions, as it is a foundational library for many Python-based services and management utilities.

Impact

Successful exploitation could lead to a denial-of-service, rendering impacted services unavailable, or the subversion of cryptographic protections intended to secure data in transit or at rest. All RHEL environments utilizing the affected library are at risk.

Recommendation

Prioritize the identification and patching of systems running the affected python-cryptography versions. Use package management tools to audit installed versions and ensure the latest security updates provided by Red Hat are applied.

Mitigations

Update python-cryptography via the Red Hat package manager (yum or dnf) to the latest secure version.

immediate IT Operations

CVE-2024-26130