PT-2023-8874 · Pypi+9 · Cryptography+9

Pkuzco

·

Published

2023-11-28

·

Updated

2025-09-17

·

CVE-2023-49083

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions cryptography versions prior to 41.0.6
Description The issue is related to the functions load pem pkcs7 certificates() and load der pkcs7 certificates() in the cryptography package, which can lead to a NULL-pointer dereference and segfault. Exploitation of this issue poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate, potentially disrupting system availability and stability.
Recommendations For versions prior to 41.0.6, update to version 41.0.6 to resolve the issue. As a temporary workaround, consider disabling the load pem pkcs7 certificates() and load der pkcs7 certificates() functions until a patch is available. Restrict access to the vulnerable functions to minimize the risk of exploitation. Avoid using the load pem pkcs7 certificates() and load der pkcs7 certificates() functions in the affected API endpoints until the issue is resolved.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2024:2337
ALSA-2024:3105
ALSA-2025:14553
ALSA-2025:15874
ALT-PU-2023-7680
ALT-PU-2023-8071
ALT-PU-2024-12946
ALT-PU-2024-15774
ALT-PU-2024-9926
AZL-32051
AZL-35128
BDU:2024-02534
CESA-2024_3105
CESA-2025_14553
CVE-2023-49083
DLA-3922-1
GHSA-JFHM-5GHH-2F97
INFSA-2024_2337
INFSA-2024_3105
INFSA-2025_14553
INFSA-2025_15874
MGASA-2025-0069
OESA-2023-1887
OPENSUSE-SU-2023_4842-1
OPENSUSE-SU-2023_4843-1
OPENSUSE-SU-2024:13472-1
PYSEC-2023-254
RHSA-2024:10965
RHSA-2024:1640
RHSA-2024:1878
RHSA-2024:2337
RHSA-2024:3105
RHSA-2024:3781
RHSA-2024_2337
RHSA-2024_3105
RHSA-2025:13098
RHSA-2025:13100
RHSA-2025:13101
RHSA-2025:13102
RHSA-2025:13103
RHSA-2025:13104
RHSA-2025:14553
RHSA-2025:15874
RHSA-2025_14553
RHSA-2025_15874
RLSA-2024:2337
SUSE-SU-2023:4842-1
SUSE-SU-2023:4843-1
SUSE-SU-2023:4844-1
SUSE-SU-2023:4921-1
SUSE-SU-2023_4843-1
SUSE-SU-2023_4844-1
SUSE-SU-2024:2375-1
USN-6539-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Cryptography