suse · CVE-2026-39892

Quick triage

Priority: medium Published: 2026-04-16 13:21:39 UTC Updated: 2026-04-16 13:21:39 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-39892 severity moderate: SUSE including 9 source package names (python-cryptography, python2-cryptography, …), 63 product×package rows across 28 product lines (SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS, … (28 product lines)): Known Not Affected 60, Fixed 3.

Description:

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

cvelogic Threat Intelligence