Bug 1217592 (CVE-2023-49083) - VUL-0: CVE-2023-49083: python-cryptography,python3-cryptography: NULL pointer dereference when loading certificates from a PKCS#7 bundle
Summary: VUL-0: CVE-2023-49083: python-cryptography,python3-cryptography: NULL pointer...
Status: RESOLVED FIXED
Alias: CVE-2023-49083
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/386323/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-49083:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-28 12:43 UTC by Carlos López
Modified: 2024-07-19 12:42 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2023-11-28 12:43:51 UTC
CVE-2023-49083

A null-pointer-dereference and segfault could occur when loading certificates from a PKCS#7 bundle.

References:
https://cryptography.io/en/latest/changelog/#v41-0-6
Comment 1 OBSbugzilla Bot 2023-11-28 13:25:02 UTC
This is an autogenerated message for OBS integration:
This bug (1217592) was mentioned in
https://build.opensuse.org/request/show/1129560 Factory / python-cryptography
Comment 3 Matej Cepl 2023-11-28 14:32:10 UTC
I have as affected these channels (everything less than 41.0.6):

ALP:Source:Standard:1.0 SUBMITTED
SLE-12-SP2:Update
SLE-12-SP3:Update:Products:Cloud8:Update
SLE-12-SP4:Update:Products:Cloud9:Update
SLE-15-SP1:Update
SLE-15-SP2:Update
SLE-15-SP4:Update
openSUSE:Factory SUBMITTED
Comment 5 Daniel Garcia 2023-11-29 07:37:35 UTC
(In reply to Matej Cepl from comment #3)
> I have as affected these channels (everything less than 41.0.6):
> 
> ALP:Source:Standard:1.0 SUBMITTED
> SLE-12-SP2:Update
> SLE-12-SP3:Update:Products:Cloud8:Update
> SLE-12-SP4:Update:Products:Cloud9:Update
> SLE-15-SP1:Update
> SLE-15-SP2:Update
> SLE-15-SP4:Update
> openSUSE:Factory SUBMITTED

The vulnerability was introduced with the addition of PKCS7 certificate parsing [1], so anything older than 3.1 [2] is not affected, so this is the list of affected channels updated:

ALP:Source:Standard:1.0 SUBMITTED
openSUSE:Factory SUBMITTED
SLE-15-SP4:Update (41.0.3) SUBMITTED
SLE-12-SP2:Update (2.8) NOT AFFECTED
SLE-12-SP3:Update:Products:Cloud8:Update (2.0.3) NOT AFFECTED
SLE-12-SP4:Update:Products:Cloud9:Update (2.3.1) NOT AFFECTED
SLE-15-SP1:Update (3.3.2)
SLE-15-SP2:Update (3.3.2)
SLE-15-SP4:Update/python3-cryptography (3.3.2)

[1] https://github.com/pyca/cryptography/commit/c898871daac710f00154cb7041e3876fc66c1ef5
[2] https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst#31---2020-08-26
Comment 8 Maintenance Automation 2023-12-14 12:30:21 UTC
SUSE-SU-2023:4844-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1217592
CVE References: CVE-2023-49083
Sources used:
Public Cloud Module 15-SP1 (src): python-cryptography-3.3.2-150100.7.18.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Maintenance Automation 2023-12-14 12:30:24 UTC
SUSE-SU-2023:4843-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1217592
CVE References: CVE-2023-49083
Sources used:
openSUSE Leap 15.4 (src): python3-cryptography-3.3.2-150400.23.1
openSUSE Leap Micro 5.3 (src): python3-cryptography-3.3.2-150400.23.1
openSUSE Leap Micro 5.4 (src): python3-cryptography-3.3.2-150400.23.1
openSUSE Leap 15.5 (src): python3-cryptography-3.3.2-150400.23.1
SUSE Linux Enterprise Micro for Rancher 5.3 (src): python3-cryptography-3.3.2-150400.23.1
SUSE Linux Enterprise Micro 5.3 (src): python3-cryptography-3.3.2-150400.23.1
SUSE Linux Enterprise Micro for Rancher 5.4 (src): python3-cryptography-3.3.2-150400.23.1
SUSE Linux Enterprise Micro 5.4 (src): python3-cryptography-3.3.2-150400.23.1
SUSE Linux Enterprise Micro 5.5 (src): python3-cryptography-3.3.2-150400.23.1
Basesystem Module 15-SP4 (src): python3-cryptography-3.3.2-150400.23.1
Basesystem Module 15-SP5 (src): python3-cryptography-3.3.2-150400.23.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Maintenance Automation 2023-12-14 12:30:27 UTC
SUSE-SU-2023:4842-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1217592
CVE References: CVE-2023-49083
Sources used:
openSUSE Leap 15.4 (src): python-cryptography-test-41.0.3-150400.16.12.1, python-cryptography-41.0.3-150400.16.12.1
openSUSE Leap 15.5 (src): python-cryptography-41.0.3-150400.16.12.1
Python 3 Module 15-SP4 (src): python-cryptography-41.0.3-150400.16.12.1
Python 3 Module 15-SP5 (src): python-cryptography-41.0.3-150400.16.12.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Maintenance Automation 2023-12-20 12:30:11 UTC
SUSE-SU-2023:4921-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1217592
CVE References: CVE-2023-49083
Sources used:
SUSE Linux Enterprise Micro 5.1 (src): python-cryptography-3.3.2-150200.22.1
SUSE Linux Enterprise Micro 5.2 (src): python-cryptography-3.3.2-150200.22.1
SUSE Linux Enterprise Micro for Rancher 5.2 (src): python-cryptography-3.3.2-150200.22.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Maintenance Automation 2024-07-09 20:30:57 UTC
SUSE-SU-2024:2375-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1217592
CVE References: CVE-2023-49083
Maintenance Incident: [SUSE:Maintenance:31650](https://smelt.suse.de/incident/31650/)
Sources used:
SUSE Linux Enterprise Micro 5.5 (src):
 python3-cryptography-3.3.2-150400.23.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.