CVE-2026-39892

Red Hat Security Advisory: RHOAI 3.3.5 - Red Hat OpenShift AI

criticalEPSS 0.7 %

Beschreibung

Die Kryptographie ist ein Paket, das kryptografische Primitive und Rezepte für Python-Entwickler bereitstellt. Von Version 45.0.0 bis vor 46.0.7 konnte das Übergeben eines nicht zusammenhängenden Puffers an APIs, die Python-Puffer akzeptieren (z.B. Hash.update()), zu Pufferüberläufen führen. Dieser Schwachpunkt wurde in der Version 46.0.7 behoben.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.8
Quelle: nvd-v3
49.2 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.7 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-09 11:57 UTC
CWE-119

Weakness-Klassen (CWE)

  • CWE-119Class

    Improper Restriction of Operations within the Bounds of a Memory Buffer

    The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-10 13:20 UTC· security-advisories@github.com
    • Reference: https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq
    • Reference: https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq
    • Reference Type: https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq Types: Vendor Advisory
  2. CVE Modified2026-09-10 13:20 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/04/08/12
    • Reference: http://www.openwall.com/lists/oss-security/2026/04/08/12
    • Reference Type: http://www.openwall.com/lists/oss-security/2026/04/08/12 Types: Mailing List, Release Notes, Third Party Advisory
  3. CVE Modified2026-09-10 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/39xxx/CVE-2026-39892.json">CVE-2026-39892</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:19375
    • Reference: https://access.redhat.com/errata/RHSA-2026:20338
    • Reference: https://access.redhat.com/errata/RHSA-2026:21017
  4. CVE Modified2026-07-30 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 (+93)Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 (+93)
  5. CVE Modified2026-07-28 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:46956
    • Affected: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 (+92)Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 (+93)

Betroffene Betriebssysteme

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux_ai3.0

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • aiohttp

    aiohttp3.13.3

  • aiohttp

    aiohttp3.14.0

  • bitnami

    mlflow

  • cryptography.io

    cryptography45.0.0 – 46.0.7

  • danthedeckie

    simpleeval1.0.5

  • encode

    starlette0.8.3 – 1.0.1

  • golang

    crypto0.52.0

  • golang

    go1.25.0 – 1.25.6

  • golang

    go1.24.12

  • grpc

    grpc1.79.3

  • huggingface

    transformers

  • IBM

    Concert< 3.0.0

    gefixt in 3.0.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • keras

    keras

  • langchain

    langchain_core1.2.22

  • nltk

    nltk3.9.3

  • protobufjs_project

    protobufjs7.5.5

  • protobufjs_project

    protobufjs

  • pyasn1

    pyasn10.6.2

  • pyasn1

    pyasn10.6.3

  • pyjwt_project

    pyjwt2.12.0

  • pyjwt_project

    pyjwt2.13.0

  • pypa

    pip26.1.2

  • pypi

    multipart0.1

Quellen & Referenzen

Verknüpfte CVEs

7 weitere CVEs anzeigen
IDCVE-2026-39892