[ALSA-2026:64795] Important: python3.14-cryptography security update
Type:
security
Severity:
important
Release date:
2026-09-08
Description:
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python-cryptography: python-cryptography: Duplicate self-signed intermediates can cause exponential path-building (CVE-2026-69249) * python-cryptography: python-cryptography: python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees (CVE-2026-69248) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
s390x python3.14-cryptography-45.0.4-4.el10_2.5.s390x.rpm af32dbd7cadb9a07a2dae959812e7c82076ade25b9087ecb9aa47c09fc825470
x86_64 python3.14-cryptography-45.0.4-4.el10_2.5.x86_64.rpm 77debc3844f9fef8f7c321e66cc7d1edd9aa9f72186a0962f05f40b265675eb7
x86_64_v2 python3.14-cryptography-45.0.4-4.el10_2.5.x86_64_v2.rpm 7feb7fd760ff25dc94a7f6ab0caf0b2308f596e433687c8361ed1219f18f98ea
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.