Ubuntu alert USN-8335-1 (pyopenssl)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8335-1] pyOpenSSL vulnerability | |
| Date: | Thu, 28 May 2026 14:15:39 +0000 | |
| Message-ID: | <E1wSbWN-0004bG-DR@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8335-1 May 28, 2026 pyopenssl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: pyOpenSSL could allow unintended access to network services. Software Description: - pyopenssl: Python wrapper around the OpenSSL library Details: It was discovered that pyOpenSSL incorrectly handled exceptions in the tlsext_servername callback. This could result in connections being accepted after an exception, contrary to expectations. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS python-openssl 19.0.0-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-openssl 19.0.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS python-openssl 17.5.0-1ubuntu1+esm1 Available with Ubuntu Pro python3-openssl 17.5.0-1ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS python-openssl 0.15.1-2ubuntu0.2+esm1 Available with Ubuntu Pro python3-openssl 0.15.1-2ubuntu0.2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8335-1 CVE-2026-27448
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoYTbcACgkQcpJm3tlz hgEmvRAAz/WadQ5MFHyzuCanm9OsbKBwMiNUMwCgGGaFoF0ydBNGDcnBGvt4mME0 yNkxWPZ6BPmn/VjWUmeWXpug+snCJn27+OV43CRClVG936v0WcNH9izOFxgSndM7 f7ce/86T7qV/CeyMb1UIwvM2lHi2CVJ87pVQb6GLAT0YWcwKta2Ou/nFNE3YrK36 lVuW9ZuFZGtLuOzWM/b5pYF1lN0jnRN7n2K8DNunBBNKiAYpxP+FvLfRKe1qKGZf MRuQni4ADPvbVJcdc2HPcvurU/ptmyIodEpgPOoinICgk5YwTj0eGCJ2JCh8Vd1x r0iqjbLa15KImDdVM4St8hbZQlcyNMGhM0XTFtZBX6NMG2932/nA006PyuP6gsUj jrX2yhM8AHs74/r2QNWMaOtEkHG/xAy3oyrAANR3UDSjMs5K8Et0ghE+KCoz7dl5 CBxQjPdOJJPy6hlvto0G1/4THeGTsWRVwiw0hDlTYhc4cuAYBsQwRIfqfk5HDg8T hk6V9R9O8EQLZv1yKUop9sQa8P+BRcBTAk3i0Tff/LygSr7Omz481J9WCJaaOwvA ecXzyfSqLD+HZ60Izhb+V68992v8/djwpKtrnhyhxSQKOTSG/Fr2FSwYV43qIgFj QfGAE6P4iuF/tadUefL45DrSHI5GnDfgPZjA5JK5cNFHBJvyOmU= =ZGnA -----END PGP SIGNATURE-----
