Home / mailings [USN-8115-1] pyOpenSSL vulnerabilities
Posted on 23 March 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8115-1
March 23, 2026
pyopenssl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 25.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in pyOpenSSL.
Software Description:
- pyopenssl: Python wrapper around the OpenSSL library
Details:
It was discovered that pyOpenSSL incorrectly handled exceptions in the
tlsext_servername callback. This could result in connections being
accepted after an exception, contrary to expectations. (CVE-2026-27448)
It was discovered that pyOpenSSL incorrectly handled the DTLS cookie
generation callback. If a callback provided cookie values greater than 256
bytes, an attacker could use this issue to cause pyOpenSSL to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2026-27459)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 25.10
python3-openssl 25.0.0-1ubuntu0.1
Ubuntu 24.04 LTS
python3-openssl 23.2.0-1ubuntu0.1
Ubuntu 22.04 LTS
python3-openssl 21.0.0-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8115-1
CVE-2026-27448, CVE-2026-27459
Package Information:
https://launchpad.net/ubuntu/+source/pyopenssl/25.0.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/pyopenssl/23.2.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/pyopenssl/21.0.0-1ubuntu0.1
--===============7571357247732328744==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
