Upstream information

CVE-2023-23931 at MITRE

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having low severity.

CVSS v3 Scores
  National Vulnerability Database SUSE
Base Score 4.8 4
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector Network Local
Attack Complexity High Low
Privileges Required None None
User Interaction None None
Scope Unchanged Unchanged
Confidentiality Impact None None
Integrity Impact Low Low
Availability Impact Low None
CVSSv3 Version 3.1 3.1
SUSE Bugzilla entry: 1208036 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
Container ses/7.1/cephcsi/cephcsi:3.8.0.1.0.4.5.4
Container ses/7.1/rook/ceph:1.10.1.16.4.5.392
Image SLES15-SP2-BYOS-Azure
Image SLES15-SP2-HPC-BYOS-Azure
Image SLES15-SP2-SAP-Azure
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP2-SAP-BYOS-Azure
Image SLES15-SP2-SAP-BYOS-EC2-HVM
Image SLES15-SP2-SAP-BYOS-GCE
Image SLES15-SP2-SAP-EC2-HVM
Image SLES15-SP2-SAP-GCE
Image SLES15-SP3-BYOS-Azure
Image SLES15-SP3-CHOST-BYOS-Aliyun
Image SLES15-SP3-CHOST-BYOS-Azure
Image SLES15-SP3-CHOST-BYOS-EC2
Image SLES15-SP3-CHOST-BYOS-SAP-CCloud
Image SLES15-SP3-HPC-BYOS-Azure
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE
Image SLES15-SP3-Micro-5-1-BYOS-Azure
Image SLES15-SP3-Micro-5-1-BYOS-EC2-HVM
Image SLES15-SP3-Micro-5-1-BYOS-GCE
Image SLES15-SP3-Micro-5-2-BYOS-Azure
Image SLES15-SP3-Micro-5-2-BYOS-EC2-HVM
Image SLES15-SP3-Micro-5-2-BYOS-GCE
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP3-SAP-BYOS-Azure
Image SLES15-SP3-SAP-BYOS-EC2-HVM
Image SLES15-SP3-SAP-BYOS-GCE
  • python3-cryptography >= 3.3.2-150200.19.1
Container suse/389-ds:2.2-14.1
Container suse/manager/4.3/proxy-httpd:4.3.5.9.28.2
Container suse/manager/4.3/proxy-tftpd:4.3.5.9.18.1
Container suse/manager/5.0/x86_64/proxy-httpd:latest
Container suse/manager/5.0/x86_64/proxy-tftpd:latest
Container suse/manager/5.0/x86_64/server:5.0.0-beta1.2.122
Image SLES15-SP4
Image SLES15-SP4-Azure-Basic
Image SLES15-SP4-Azure-Standard
Image SLES15-SP4-BYOS
Image SLES15-SP4-BYOS-Azure
Image SLES15-SP4-BYOS-EC2
Image SLES15-SP4-BYOS-GCE
Image SLES15-SP4-CHOST-BYOS
Image SLES15-SP4-CHOST-BYOS-Aliyun
Image SLES15-SP4-CHOST-BYOS-Azure
Image SLES15-SP4-CHOST-BYOS-EC2
Image SLES15-SP4-CHOST-BYOS-GCE
Image SLES15-SP4-CHOST-BYOS-SAP-CCloud
Image SLES15-SP4-EC2
Image SLES15-SP4-EC2-ECS-HVM
Image SLES15-SP4-GCE
Image SLES15-SP4-HPC
Image SLES15-SP4-HPC-Azure
Image SLES15-SP4-HPC-BYOS
Image SLES15-SP4-HPC-BYOS-Azure
Image SLES15-SP4-HPC-BYOS-EC2
Image SLES15-SP4-HPC-BYOS-GCE
Image SLES15-SP4-HPC-EC2
Image SLES15-SP4-HPC-GCE
Image SLES15-SP4-Hardened-BYOS
Image SLES15-SP4-Hardened-BYOS-Azure
Image SLES15-SP4-Hardened-BYOS-EC2
Image SLES15-SP4-Hardened-BYOS-GCE
Image SLES15-SP4-Manager-Proxy-4-3-BYOS
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE
Image SLES15-SP4-Manager-Server-4-3
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
Image SLES15-SP4-Manager-Server-4-3-BYOS
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
Image SLES15-SP4-Micro-5-3
Image SLES15-SP4-Micro-5-3-Azure
Image SLES15-SP4-Micro-5-3-BYOS
Image SLES15-SP4-Micro-5-3-BYOS-Azure
Image SLES15-SP4-Micro-5-3-BYOS-EC2
Image SLES15-SP4-Micro-5-3-BYOS-GCE
Image SLES15-SP4-Micro-5-3-EC2
Image SLES15-SP4-Micro-5-3-GCE
Image SLES15-SP4-Micro-5-4
Image SLES15-SP4-Micro-5-4-Azure
Image SLES15-SP4-Micro-5-4-BYOS
Image SLES15-SP4-Micro-5-4-BYOS-Azure
Image SLES15-SP4-Micro-5-4-BYOS-EC2
Image SLES15-SP4-Micro-5-4-BYOS-GCE
Image SLES15-SP4-Micro-5-4-EC2
Image SLES15-SP4-Micro-5-4-GCE
Image SLES15-SP4-SAP
Image SLES15-SP4-SAP-Azure
Image SLES15-SP4-SAP-Azure-LI-BYOS
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
Image SLES15-SP4-SAP-Azure-VLI-BYOS
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP4-SAP-BYOS
Image SLES15-SP4-SAP-BYOS-Azure
Image SLES15-SP4-SAP-BYOS-EC2
Image SLES15-SP4-SAP-BYOS-GCE
Image SLES15-SP4-SAP-EC2
Image SLES15-SP4-SAP-GCE
Image SLES15-SP4-SAP-Hardened
Image SLES15-SP4-SAP-Hardened-Azure
Image SLES15-SP4-SAP-Hardened-BYOS
Image SLES15-SP4-SAP-Hardened-BYOS-Azure
Image SLES15-SP4-SAP-Hardened-BYOS-EC2
Image SLES15-SP4-SAP-Hardened-BYOS-GCE
Image SLES15-SP4-SAP-Hardened-EC2
Image SLES15-SP4-SAP-Hardened-GCE
Image SLES15-SP4-SAPCAL
Image SLES15-SP4-SAPCAL-Azure
Image SLES15-SP4-SAPCAL-EC2
Image SLES15-SP4-SAPCAL-GCE
Image SLES15-SP4-SUSE-Rancher-Setup-BYOS
Image SLES15-SP4-SUSE-Rancher-Setup-BYOS-EC2
Image SLES15-SP5-Azure-Basic
Image SLES15-SP5-Azure-Standard
Image SLES15-SP5-BYOS-Azure
Image SLES15-SP5-BYOS-EC2
Image SLES15-SP5-BYOS-GCE
Image SLES15-SP5-CHOST-BYOS-Aliyun
Image SLES15-SP5-CHOST-BYOS-Azure
Image SLES15-SP5-CHOST-BYOS-EC2
Image SLES15-SP5-CHOST-BYOS-GCE
Image SLES15-SP5-CHOST-BYOS-SAP-CCloud
Image SLES15-SP5-EC2
Image SLES15-SP5-EC2-ECS-HVM
Image SLES15-SP5-GCE
Image SLES15-SP5-HPC-Azure
Image SLES15-SP5-HPC-BYOS-Azure
Image SLES15-SP5-HPC-BYOS-EC2
Image SLES15-SP5-HPC-BYOS-GCE
Image SLES15-SP5-HPC-EC2
Image SLES15-SP5-HPC-GCE
Image SLES15-SP5-Hardened-BYOS-Azure
Image SLES15-SP5-Hardened-BYOS-EC2
Image SLES15-SP5-Hardened-BYOS-GCE
Image SLES15-SP5-Micro-5-5
Image SLES15-SP5-Micro-5-5-Azure
Image SLES15-SP5-Micro-5-5-BYOS
Image SLES15-SP5-Micro-5-5-BYOS-Azure
Image SLES15-SP5-Micro-5-5-BYOS-EC2
Image SLES15-SP5-Micro-5-5-BYOS-GCE
Image SLES15-SP5-Micro-5-5-EC2
Image SLES15-SP5-Micro-5-5-GCE
Image SLES15-SP5-SAP-Azure
Image SLES15-SP5-SAP-Azure-LI-BYOS
Image SLES15-SP5-SAP-Azure-LI-BYOS-Production
Image SLES15-SP5-SAP-Azure-VLI-BYOS
Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP5-SAP-BYOS-Azure
Image SLES15-SP5-SAP-BYOS-EC2
Image SLES15-SP5-SAP-BYOS-GCE
Image SLES15-SP5-SAP-EC2
Image SLES15-SP5-SAP-GCE
Image SLES15-SP5-SAP-Hardened-Azure
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
Image SLES15-SP5-SAP-Hardened-BYOS-GCE
Image SLES15-SP5-SAP-Hardened-EC2
Image SLES15-SP5-SAP-Hardened-GCE
Image SLES15-SP5-SAPCAL-Azure
Image SLES15-SP5-SAPCAL-EC2
Image SLES15-SP5-SAPCAL-GCE
  • python3-cryptography >= 3.3.2-150400.16.6.1
HPE Helion OpenStack 8
  • python-cffi >= 1.10.0-4.3.1
  • python-cryptography >= 2.0.3-3.14.2
  • venv-openstack-aodh-x86_64 >= 5.1.1~dev7-12.44.1
  • venv-openstack-barbican-x86_64 >= 5.0.2~dev3-12.47.1
  • venv-openstack-ceilometer-x86_64 >= 9.0.8~dev7-12.42.1
  • venv-openstack-cinder-x86_64 >= 11.2.3~dev29-14.46.1
  • venv-openstack-designate-x86_64 >= 5.0.3~dev7-12.43.1
  • venv-openstack-freezer-x86_64 >= 5.0.0.0~xrc2~dev2-10.40.1
  • venv-openstack-glance-x86_64 >= 15.0.3~dev3-12.43.1
  • venv-openstack-heat-x86_64 >= 9.0.8~dev22-12.49.1
  • venv-openstack-horizon-hpe-x86_64 >= 12.0.5~dev6-14.52.1
  • venv-openstack-ironic-x86_64 >= 9.1.8~dev8-12.45.1
  • venv-openstack-keystone-x86_64 >= 12.0.4~dev11-11.49.1
  • venv-openstack-magnum-x86_64 >= 5.0.2_5.0.2_5.0.2~dev31-11.44.1
  • venv-openstack-manila-x86_64 >= 5.1.1~dev5-12.49.1
  • venv-openstack-monasca-ceilometer-x86_64 >= 1.5.1_1.5.1_1.5.1~dev3-8.40.1
  • venv-openstack-monasca-x86_64 >= 2.2.2~dev1-11.49.1
  • venv-openstack-murano-x86_64 >= 4.0.2~dev3-12.42.1
  • venv-openstack-neutron-x86_64 >= 11.0.9~dev69-13.50.1
  • venv-openstack-nova-x86_64 >= 16.1.9~dev92-11.48.1
  • venv-openstack-octavia-x86_64 >= 1.0.6~dev3-12.45.1
  • venv-openstack-sahara-x86_64 >= 7.0.5~dev4-11.44.1
  • venv-openstack-swift-x86_64 >= 2.15.2_2.15.2_2.15.2~dev32-11.35.1
  • venv-openstack-trove-x86_64 >= 8.0.2~dev2-11.44.1
Patchnames:
HPE-Helion-OpenStack-8-2023-2144
HPE-Helion-OpenStack-8-2023-839
Image SLES12-SP5-Azure-BYOS
Image SLES12-SP5-Azure-HPC-BYOS
Image SLES12-SP5-Azure-SAP-BYOS
Image SLES12-SP5-Azure-SAP-On-Demand
Image SLES12-SP5-EC2-BYOS
Image SLES12-SP5-EC2-ECS-On-Demand
Image SLES12-SP5-EC2-On-Demand
Image SLES12-SP5-EC2-SAP-BYOS
Image SLES12-SP5-EC2-SAP-On-Demand
Image SLES12-SP5-GCE-BYOS
Image SLES12-SP5-GCE-SAP-BYOS
Image SLES12-SP5-GCE-SAP-On-Demand
  • python-cffi >= 1.11.5-5.19.1
  • python-cryptography >= 2.8-7.40.1
  • python3-cffi >= 1.11.5-5.19.1
  • python3-cryptography >= 2.8-7.40.1
Image SLES12-SP5-Azure-Basic-On-Demand
Image SLES12-SP5-Azure-HPC-On-Demand
Image SLES12-SP5-Azure-Standard-On-Demand
Image SLES12-SP5-GCE-On-Demand
  • python3-cffi >= 1.11.5-5.19.1
  • python3-cryptography >= 2.8-7.40.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
  • python-cffi >= 1.11.5-5.19.1
  • python-cryptography >= 2.8-7.40.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
  • python3-cryptography >= 2.9.2-150100.7.12.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
Image SLES15-SP3-SAPCAL-Azure
  • python2-cryptography >= 3.3.2-150200.19.1
  • python3-cryptography >= 3.3.2-150200.19.1
SUSE CaaS Platform 4.0
  • python2-cryptography >= 2.9.2-150100.7.12.1
  • python3-cryptography >= 2.9.2-150100.7.12.1
Patchnames:
SUSE-SUSE-CAASP-4.0-2023-737
SUSE Liberty Linux 8
  • python3-cryptography >= 3.2.1-6.el8
Patchnames:
RHSA-2023:7096
SUSE Liberty Linux 9
  • python3-cryptography >= 36.0.1-4.el9
Patchnames:
RHSA-2023:6615
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise High Performance Computing 15 SP4
SUSE Linux Enterprise Module for Basesystem 15 SP4
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP4
SUSE Manager Proxy 4.3
SUSE Manager Retail Branch Server 4.3
SUSE Manager Server 4.3
  • python3-cryptography >= 3.3.2-150400.16.6.1
Patchnames:
SUSE-SLE-Module-Basesystem-15-SP4-2023-722
SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
  • python3-cryptography >= 3.3.2-150400.16.6.1
Patchnames:
SUSE Linux Enterprise Module for Basesystem 15 SP5 GA python-cryptography-3.3.2-150400.16.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP5 GA python3-cryptography-3.3.2-150400.16.6.1
SUSE Linux Enterprise Desktop 15 SP6
SUSE Linux Enterprise High Performance Computing 15 SP6
SUSE Linux Enterprise Module for Basesystem 15 SP6
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15 SP6
  • python3-cryptography >= 3.3.2-150400.16.6.1
Patchnames:
SUSE Linux Enterprise Module for Basesystem 15 SP6 GA python3-cryptography-3.3.2-150400.23.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
  • python2-cryptography >= 2.9.2-150100.7.12.1
  • python3-cryptography >= 2.9.2-150100.7.12.1
Patchnames:
SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-737
SUSE Linux Enterprise Micro 5.1
  • python3-cryptography >= 3.3.2-150200.19.1
Patchnames:
SUSE-SUSE-MicroOS-5.1-2023-1763
SUSE Linux Enterprise Micro 5.2
  • python3-cryptography >= 3.3.2-150200.19.1
Patchnames:
SUSE-SUSE-MicroOS-5.2-2023-1763
SUSE Linux Enterprise Micro 5.3
  • python3-cryptography >= 3.3.2-150400.16.6.1
Patchnames:
SUSE-SLE-Micro-5.3-2023-722
SUSE Linux Enterprise Micro 5.4
  • python3-cryptography >= 3.3.2-150400.16.6.1
Patchnames:
SUSE-SLE-Micro-5.4-2023-722
SUSE Linux Enterprise Real Time 15 SP3
  • python3-cryptography >= 3.3.2-150200.19.1
Patchnames:
SUSE-SLE-Product-RT-15-SP3-2023-1763
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP5
  • python-cffi >= 1.11.5-5.19.1
  • python-cryptography >= 2.8-7.40.1
  • python3-cffi >= 1.11.5-5.19.1
  • python3-cryptography >= 2.8-7.40.1
Patchnames:
SUSE-SLE-SERVER-12-SP5-2023-1767
SUSE-SLE-SERVER-12-SP5-2023-837
SUSE Linux Enterprise Server 15 SP1-LTSS
  • python2-cryptography >= 2.9.2-150100.7.12.1
  • python3-cryptography >= 2.9.2-150100.7.12.1
Patchnames:
SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-737
SUSE Linux Enterprise Server for SAP Applications 15 SP1
  • python2-cryptography >= 2.9.2-150100.7.12.1
  • python3-cryptography >= 2.9.2-150100.7.12.1
Patchnames:
SUSE-SLE-Product-SLES_SAP-15-SP1-2023-737
SUSE OpenStack Cloud 8
  • python-cffi >= 1.10.0-4.3.1
  • python-cryptography >= 2.0.3-3.14.2
  • venv-openstack-aodh-x86_64 >= 5.1.1~dev7-12.44.1
  • venv-openstack-barbican-x86_64 >= 5.0.2~dev3-12.47.1
  • venv-openstack-ceilometer-x86_64 >= 9.0.8~dev7-12.42.1
  • venv-openstack-cinder-x86_64 >= 11.2.3~dev29-14.46.1
  • venv-openstack-designate-x86_64 >= 5.0.3~dev7-12.43.1
  • venv-openstack-freezer-x86_64 >= 5.0.0.0~xrc2~dev2-10.40.1
  • venv-openstack-glance-x86_64 >= 15.0.3~dev3-12.43.1
  • venv-openstack-heat-x86_64 >= 9.0.8~dev22-12.49.1
  • venv-openstack-horizon-x86_64 >= 12.0.5~dev6-14.52.1
  • venv-openstack-ironic-x86_64 >= 9.1.8~dev8-12.45.1
  • venv-openstack-keystone-x86_64 >= 12.0.4~dev11-11.49.1
  • venv-openstack-magnum-x86_64 >= 5.0.2_5.0.2_5.0.2~dev31-11.44.1
  • venv-openstack-manila-x86_64 >= 5.1.1~dev5-12.49.1
  • venv-openstack-monasca-ceilometer-x86_64 >= 1.5.1_1.5.1_1.5.1~dev3-8.40.1
  • venv-openstack-monasca-x86_64 >= 2.2.2~dev1-11.49.1
  • venv-openstack-murano-x86_64 >= 4.0.2~dev3-12.42.1
  • venv-openstack-neutron-x86_64 >= 11.0.9~dev69-13.50.1
  • venv-openstack-nova-x86_64 >= 16.1.9~dev92-11.48.1
  • venv-openstack-octavia-x86_64 >= 1.0.6~dev3-12.45.1
  • venv-openstack-sahara-x86_64 >= 7.0.5~dev4-11.44.1
  • venv-openstack-swift-x86_64 >= 2.15.2_2.15.2_2.15.2~dev32-11.35.1
  • venv-openstack-trove-x86_64 >= 8.0.2~dev2-11.44.1
Patchnames:
SUSE-OpenStack-Cloud-8-2023-2144
SUSE-OpenStack-Cloud-8-2023-839
SUSE OpenStack Cloud 9
  • python-cffi >= 1.11.5-3.3.1
  • python-cryptography >= 2.3.1-3.6.6
  • venv-openstack-barbican-x86_64 >= 7.0.1~dev24-3.41.2
  • venv-openstack-cinder-x86_64 >= 13.0.10~dev24-3.42.3
  • venv-openstack-designate-x86_64 >= 7.0.2~dev2-3.39.2
  • venv-openstack-glance-x86_64 >= 17.0.1~dev30-3.37.2
  • venv-openstack-heat-x86_64 >= 11.0.4~dev4-3.41.2
  • venv-openstack-horizon-x86_64 >= 14.1.1~dev11-4.47.2
  • venv-openstack-ironic-x86_64 >= 11.1.5~dev18-4.37.2
  • venv-openstack-keystone-x86_64 >= 14.2.1~dev9-3.40.2
  • venv-openstack-magnum-x86_64 >= 7.2.1~dev1-4.39.3
  • venv-openstack-manila-x86_64 >= 7.4.2~dev60-3.45.2
  • venv-openstack-monasca-ceilometer-x86_64 >= 1.8.2~dev3-3.39.2
  • venv-openstack-monasca-x86_64 >= 2.7.1~dev10-3.41.2
  • venv-openstack-neutron-x86_64 >= 13.0.8~dev209-6.47.2
  • venv-openstack-nova-x86_64 >= 18.3.1~dev92-3.47.2
  • venv-openstack-octavia-x86_64 >= 3.2.3~dev7-4.39.2
  • venv-openstack-sahara-x86_64 >= 9.0.2~dev15-3.39.2
  • venv-openstack-swift-x86_64 >= 2.19.2~dev48-2.34.2
Patchnames:
SUSE-OpenStack-Cloud-9-2023-2218
SUSE-OpenStack-Cloud-9-2023-838
SUSE OpenStack Cloud Crowbar 8
  • python-cffi >= 1.10.0-4.3.1
  • python-cryptography >= 2.0.3-3.14.2
Patchnames:
SUSE-OpenStack-Cloud-Crowbar-8-2023-2144
SUSE-OpenStack-Cloud-Crowbar-8-2023-839
SUSE OpenStack Cloud Crowbar 9
  • python-cffi >= 1.11.5-3.3.1
  • python-cryptography >= 2.3.1-3.6.6
Patchnames:
SUSE-OpenStack-Cloud-Crowbar-9-2023-2218
SUSE-OpenStack-Cloud-Crowbar-9-2023-838
openSUSE Leap 15.4
  • python3-cryptography >= 3.3.2-150400.16.6.1
Patchnames:
openSUSE-SLE-15.4-2023-722
openSUSE Leap Micro 5.2
  • python3-cryptography >= 3.3.2-150200.19.1
Patchnames:
openSUSE-Leap-Micro-5.2-2023-1763
openSUSE Leap Micro 5.3
  • python3-cryptography >= 3.3.2-150400.16.6.1
Patchnames:
openSUSE-Leap-Micro-5.3-2023-722
openSUSE Tumbleweed
  • python310-cryptography >= 39.0.1-1.1
  • python310-oci-sdk >= 2.96.0-1.1
  • python311-oci-sdk >= 2.96.0-1.1
  • python38-cryptography >= 39.0.1-1.1
  • python38-oci-sdk >= 2.96.0-1.1
  • python39-cryptography >= 39.0.1-1.1
  • python39-oci-sdk >= 2.96.0-1.1
Patchnames:
openSUSE Tumbleweed GA python310-cryptography-39.0.1-1.1
openSUSE Tumbleweed GA python310-oci-sdk-2.96.0-1.1


First public cloud image revisions this CVE is fixed in:


Status of this issue by product and package

Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification. The updates are grouped by state of their lifecycle. SUSE product lifecycles are documented on the lifecycle page.

Product(s) Source package State
Products under general support and receiving all security fixes.
SUSE Enterprise Storage 7.1 python-cffi Not affected
SUSE Enterprise Storage 7.1 python-cryptography Affected
SUSE Linux Enterprise Desktop 15 SP5 python-cffi Not affected
SUSE Linux Enterprise Desktop 15 SP5 python-cryptography Released
SUSE Linux Enterprise Desktop 15 SP6 python3-cryptography Released
SUSE Linux Enterprise High Performance Computing 12 SP5 python-cffi Released
SUSE Linux Enterprise High Performance Computing 12 SP5 python-cryptography Released
SUSE Linux Enterprise High Performance Computing 15 SP5 python-cffi Not affected
SUSE Linux Enterprise High Performance Computing 15 SP5 python-cryptography Released
SUSE Linux Enterprise High Performance Computing 15 SP6 python3-cryptography Released
SUSE Linux Enterprise Micro 5.1 python-cffi Not affected
SUSE Linux Enterprise Micro 5.1 python-cryptography Released
SUSE Linux Enterprise Micro 5.2 python-cffi Not affected
SUSE Linux Enterprise Micro 5.2 python-cryptography Released
SUSE Linux Enterprise Micro 5.3 python-cffi Not affected
SUSE Linux Enterprise Micro 5.3 python-cryptography Released
SUSE Linux Enterprise Micro 5.4 python-cffi Not affected
SUSE Linux Enterprise Micro 5.4 python-cryptography Released
SUSE Linux Enterprise Micro 5.5 python-cffi Not affected
SUSE Linux Enterprise Micro for Rancher 5.2 python-cryptography Released
SUSE Linux Enterprise Micro for Rancher 5.3 python-cryptography Released
SUSE Linux Enterprise Micro for Rancher 5.4 python-cryptography Released
SUSE Linux Enterprise Module for Basesystem 15 SP5 python-cffi Not affected
SUSE Linux Enterprise Module for Basesystem 15 SP5 python-cryptography Released
SUSE Linux Enterprise Module for Basesystem 15 SP6 python3-cryptography Released
SUSE Linux Enterprise Module for Python 3 15 SP5 python-cryptography Affected
SUSE Linux Enterprise Real Time 15 SP3 python-cffi Not affected
SUSE Linux Enterprise Real Time 15 SP3 python-cryptography Released
SUSE Linux Enterprise Server 12 SP5 python-cffi Released
SUSE Linux Enterprise Server 12 SP5 python-cryptography Released
SUSE Linux Enterprise Server 15 SP5 python-cffi Not affected
SUSE Linux Enterprise Server 15 SP5 python-cryptography Released
SUSE Linux Enterprise Server 15 SP6 python3-cryptography Released
SUSE Linux Enterprise Server for SAP Applications 12 SP5 python-cffi Released
SUSE Linux Enterprise Server for SAP Applications 12 SP5 python-cryptography Released
SUSE Linux Enterprise Server for SAP Applications 15 SP5 python-cffi Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP5 python-cryptography Released
SUSE Linux Enterprise Server for SAP Applications 15 SP6 python3-cryptography Released
SUSE Manager Proxy 4.3 python-cffi Not affected
SUSE Manager Proxy 4.3 python-cryptography Released
SUSE Manager Retail Branch Server 4.3 python-cffi Not affected
SUSE Manager Retail Branch Server 4.3 python-cryptography Released
SUSE Manager Server 4.3 python-cffi Not affected
SUSE Manager Server 4.3 python-cryptography Released
openSUSE Leap Micro 5.3 python-cryptography Released
Products under Long Term Service Pack support and receiving important and critical security fixes.
SUSE Linux Enterprise Desktop 15 SP4 python-cffi Not affected
SUSE Linux Enterprise Desktop 15 SP4 python-cryptography Released
SUSE Linux Enterprise High Performance Computing 15 SP1 python-cryptography Affected
SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS python-cryptography Affected
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS python-cryptography Released
SUSE Linux Enterprise High Performance Computing 15 SP2 python-cffi Not affected
SUSE Linux Enterprise High Performance Computing 15 SP2 python-cryptography Affected
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS python-cffi Not affected
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS python-cryptography Affected
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS python-cffi Not affected
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS python-cryptography Affected
SUSE Linux Enterprise High Performance Computing 15 SP3 python-cffi Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3 python-cryptography Affected
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS python-cffi Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS python-cryptography Affected
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS python-cffi Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS python-cryptography Affected
SUSE Linux Enterprise High Performance Computing 15 SP4 python-cffi Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4 python-cryptography Released
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS python-cffi Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS python-cryptography Affected
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS python-cffi Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS python-cryptography Affected
SUSE Linux Enterprise Module for Basesystem 15 SP2 python-cffi Not affected
SUSE Linux Enterprise Module for Basesystem 15 SP2 python-cryptography Affected
SUSE Linux Enterprise Module for Basesystem 15 SP3 python-cffi Not affected
SUSE Linux Enterprise Module for Basesystem 15 SP3 python-cryptography Affected
SUSE Linux Enterprise Module for Basesystem 15 SP4 python-cffi Not affected
SUSE Linux Enterprise Module for Basesystem 15 SP4 python-cryptography Released
SUSE Linux Enterprise Module for Python 2 15 SP2 python-cffi Not affected
SUSE Linux Enterprise Module for Python 2 15 SP2 python-cryptography Affected
SUSE Linux Enterprise Module for Python 2 15 SP3 python-cffi Not affected
SUSE Linux Enterprise Module for Python 2 15 SP3 python-cryptography Affected
SUSE Linux Enterprise Module for Python 3 15 SP4 python-cryptography Affected
SUSE Linux Enterprise Server 15 SP2 python-cffi Not affected
SUSE Linux Enterprise Server 15 SP2 python-cryptography Affected
SUSE Linux Enterprise Server 15 SP2-LTSS python-cffi Not affected
SUSE Linux Enterprise Server 15 SP2-LTSS python-cryptography Affected
SUSE Linux Enterprise Server 15 SP3 python-cffi Not affected
SUSE Linux Enterprise Server 15 SP3 python-cryptography Affected
SUSE Linux Enterprise Server 15 SP3-LTSS python-cffi Not affected
SUSE Linux Enterprise Server 15 SP3-LTSS python-cryptography Affected
SUSE Linux Enterprise Server 15 SP4 python-cffi Not affected
SUSE Linux Enterprise Server 15 SP4 python-cryptography Released
SUSE Linux Enterprise Server 15 SP4-LTSS python-cffi Not affected
SUSE Linux Enterprise Server 15 SP4-LTSS python-cryptography Affected
SUSE Linux Enterprise Server for SAP Applications 15 SP2 python-cffi Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP2 python-cryptography Affected
SUSE Linux Enterprise Server for SAP Applications 15 SP3 python-cffi Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP3 python-cryptography Affected
SUSE Linux Enterprise Server for SAP Applications 15 SP4 python-cffi Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP4 python-cryptography Released
SUSE OpenStack Cloud 8 python-cffi Released
SUSE OpenStack Cloud 8 python-cryptography Released
SUSE OpenStack Cloud 8 venv-openstack-aodh Released
SUSE OpenStack Cloud 8 venv-openstack-barbican Released
SUSE OpenStack Cloud 8 venv-openstack-ceilometer Released
SUSE OpenStack Cloud 8 venv-openstack-cinder Released
SUSE OpenStack Cloud 8 venv-openstack-designate Released
SUSE OpenStack Cloud 8 venv-openstack-freezer Released
SUSE OpenStack Cloud 8 venv-openstack-glance Released
SUSE OpenStack Cloud 8 venv-openstack-heat Released
SUSE OpenStack Cloud 8 venv-openstack-horizon Released
SUSE OpenStack Cloud 8 venv-openstack-ironic Released
SUSE OpenStack Cloud 8 venv-openstack-keystone Released
SUSE OpenStack Cloud 8 venv-openstack-magnum Released
SUSE OpenStack Cloud 8 venv-openstack-manila Released
SUSE OpenStack Cloud 8 venv-openstack-monasca Released
SUSE OpenStack Cloud 8 venv-openstack-monasca-ceilometer Released
SUSE OpenStack Cloud 8 venv-openstack-murano Released
SUSE OpenStack Cloud 8 venv-openstack-neutron Released
SUSE OpenStack Cloud 8 venv-openstack-nova Released
SUSE OpenStack Cloud 8 venv-openstack-octavia Released
SUSE OpenStack Cloud 8 venv-openstack-sahara Released
SUSE OpenStack Cloud 8 venv-openstack-swift Released
SUSE OpenStack Cloud 8 venv-openstack-trove Released
SUSE OpenStack Cloud 9 python-cffi Released
SUSE OpenStack Cloud 9 python-cryptography Released
SUSE OpenStack Cloud 9 venv-openstack-barbican Released
SUSE OpenStack Cloud 9 venv-openstack-cinder Released
SUSE OpenStack Cloud 9 venv-openstack-designate Released
SUSE OpenStack Cloud 9 venv-openstack-glance Released
SUSE OpenStack Cloud 9 venv-openstack-heat Released
SUSE OpenStack Cloud 9 venv-openstack-horizon Released
SUSE OpenStack Cloud 9 venv-openstack-ironic Released
SUSE OpenStack Cloud 9 venv-openstack-keystone Released
SUSE OpenStack Cloud 9 venv-openstack-magnum Released
SUSE OpenStack Cloud 9 venv-openstack-manila Released
SUSE OpenStack Cloud 9 venv-openstack-monasca Released
SUSE OpenStack Cloud 9 venv-openstack-monasca-ceilometer Released
SUSE OpenStack Cloud 9 venv-openstack-neutron Released
SUSE OpenStack Cloud 9 venv-openstack-nova Released
SUSE OpenStack Cloud 9 venv-openstack-octavia Released
SUSE OpenStack Cloud 9 venv-openstack-sahara Released
SUSE OpenStack Cloud 9 venv-openstack-swift Released
Products past their end of life and not receiving proactive updates anymore.
HPE Helion OpenStack 8 python-cffi Released
HPE Helion OpenStack 8 python-cryptography Released
HPE Helion OpenStack 8 venv-openstack-aodh Released
HPE Helion OpenStack 8 venv-openstack-barbican Released
HPE Helion OpenStack 8 venv-openstack-ceilometer Released
HPE Helion OpenStack 8 venv-openstack-cinder Released
HPE Helion OpenStack 8 venv-openstack-designate Released
HPE Helion OpenStack 8 venv-openstack-freezer Released
HPE Helion OpenStack 8 venv-openstack-glance Released
HPE Helion OpenStack 8 venv-openstack-heat Released
HPE Helion OpenStack 8 venv-openstack-horizon-hpe Released
HPE Helion OpenStack 8 venv-openstack-ironic Released
HPE Helion OpenStack 8 venv-openstack-keystone Released
HPE Helion OpenStack 8 venv-openstack-magnum Released
HPE Helion OpenStack 8 venv-openstack-manila Released
HPE Helion OpenStack 8 venv-openstack-monasca Released
HPE Helion OpenStack 8 venv-openstack-monasca-ceilometer Released
HPE Helion OpenStack 8 venv-openstack-murano Released
HPE Helion OpenStack 8 venv-openstack-neutron Released
HPE Helion OpenStack 8 venv-openstack-nova Released
HPE Helion OpenStack 8 venv-openstack-octavia Released
HPE Helion OpenStack 8 venv-openstack-sahara Released
HPE Helion OpenStack 8 venv-openstack-swift Released
HPE Helion OpenStack 8 venv-openstack-trove Released
SUSE CaaS Platform 3.0 python-cffi Affected
SUSE CaaS Platform 3.0 python-cryptography Affected
SUSE CaaS Platform 4.0 python-cryptography Released
SUSE Enterprise Storage 6 python-cryptography Affected
SUSE Enterprise Storage 7 python-cffi Not affected
SUSE Enterprise Storage 7 python-cryptography Affected
SUSE Linux Enterprise Desktop 12 SP2 python-cffi Affected
SUSE Linux Enterprise Desktop 12 SP2 python-cryptography Affected
SUSE Linux Enterprise Desktop 12 SP3 python-cffi Affected
SUSE Linux Enterprise Desktop 12 SP3 python-cryptography Affected
SUSE Linux Enterprise Desktop 12 SP4 python-cffi Affected
SUSE Linux Enterprise Desktop 12 SP4 python-cryptography Affected
SUSE Linux Enterprise Desktop 15 SP1 python-cryptography Affected
SUSE Linux Enterprise Desktop 15 SP2 python-cffi Not affected
SUSE Linux Enterprise Desktop 15 SP2 python-cryptography Affected
SUSE Linux Enterprise Desktop 15 SP3 python-cffi Not affected
SUSE Linux Enterprise Desktop 15 SP3 python-cryptography Affected
SUSE Linux Enterprise Micro 5.0 python-cffi Not affected
SUSE Linux Enterprise Micro 5.0 python-cryptography Affected
SUSE Linux Enterprise Module for Basesystem 15 SP1 python-cryptography Affected
SUSE Linux Enterprise Module for Public Cloud 15 SP1 python-cryptography Affected
SUSE Linux Enterprise Real Time 15 SP2 python-cffi Not affected
SUSE Linux Enterprise Real Time 15 SP2 python-cryptography Affected
SUSE Linux Enterprise Real Time 15 SP4 python-cffi Not affected
SUSE Linux Enterprise Server 12 SP2 python-cffi Affected
SUSE Linux Enterprise Server 12 SP2 python-cryptography Affected
SUSE Linux Enterprise Server 12 SP2-BCL python-cffi Affected
SUSE Linux Enterprise Server 12 SP2-BCL python-cryptography Affected
SUSE Linux Enterprise Server 12 SP2-ESPOS python-cffi Affected
SUSE Linux Enterprise Server 12 SP2-ESPOS python-cryptography Affected
SUSE Linux Enterprise Server 12 SP2-LTSS python-cffi Affected
SUSE Linux Enterprise Server 12 SP2-LTSS python-cryptography Affected
SUSE Linux Enterprise Server 12 SP3 python-cffi Affected
SUSE Linux Enterprise Server 12 SP3 python-cryptography Affected
SUSE Linux Enterprise Server 12 SP3-BCL python-cffi Affected
SUSE Linux Enterprise Server 12 SP3-BCL python-cryptography Affected
SUSE Linux Enterprise Server 12 SP3-ESPOS python-cffi Affected
SUSE Linux Enterprise Server 12 SP3-ESPOS python-cryptography Affected
SUSE Linux Enterprise Server 12 SP3-LTSS python-cffi Affected
SUSE Linux Enterprise Server 12 SP3-LTSS python-cryptography Affected
SUSE Linux Enterprise Server 12 SP4 python-cffi Affected
SUSE Linux Enterprise Server 12 SP4 python-cryptography Affected
SUSE Linux Enterprise Server 12 SP4-ESPOS python-cffi Affected
SUSE Linux Enterprise Server 12 SP4-ESPOS python-cryptography Affected
SUSE Linux Enterprise Server 12 SP4-LTSS python-cffi Affected
SUSE Linux Enterprise Server 12 SP4-LTSS python-cryptography Affected
SUSE Linux Enterprise Server 15 SP1 python-cryptography Affected
SUSE Linux Enterprise Server 15 SP1-BCL python-cryptography Affected
SUSE Linux Enterprise Server 15 SP1-LTSS python-cryptography Released
SUSE Linux Enterprise Server 15 SP2-BCL python-cffi Not affected
SUSE Linux Enterprise Server 15 SP2-BCL python-cryptography Affected
SUSE Linux Enterprise Server 15 SP3-BCL python-cffi Not affected
SUSE Linux Enterprise Server 15 SP3-BCL python-cryptography Affected
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 python-cffi Affected
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 python-cryptography Affected
SUSE Linux Enterprise Server for SAP Applications 12 SP2 python-cffi Affected
SUSE Linux Enterprise Server for SAP Applications 12 SP2 python-cryptography Affected
SUSE Linux Enterprise Server for SAP Applications 12 SP3 python-cffi Affected
SUSE Linux Enterprise Server for SAP Applications 12 SP3 python-cryptography Affected
SUSE Linux Enterprise Server for SAP Applications 12 SP4 python-cffi Affected
SUSE Linux Enterprise Server for SAP Applications 12 SP4 python-cryptography Affected
SUSE Linux Enterprise Server for SAP Applications 15 SP1 python-cryptography Released
SUSE Manager Proxy 4.0 python-cryptography Affected
SUSE Manager Proxy 4.1 python-cffi Not affected
SUSE Manager Proxy 4.1 python-cryptography Affected
SUSE Manager Proxy 4.2 python-cffi Not affected
SUSE Manager Proxy 4.2 python-cryptography Affected
SUSE Manager Retail Branch Server 4.0 python-cryptography Affected
SUSE Manager Retail Branch Server 4.1 python-cffi Not affected
SUSE Manager Retail Branch Server 4.1 python-cryptography Affected
SUSE Manager Retail Branch Server 4.2 python-cffi Not affected
SUSE Manager Retail Branch Server 4.2 python-cryptography Affected
SUSE Manager Server 4.0 python-cryptography Affected
SUSE Manager Server 4.1 python-cffi Not affected
SUSE Manager Server 4.1 python-cryptography Affected
SUSE Manager Server 4.2 python-cffi Not affected
SUSE Manager Server 4.2 python-cryptography Affected
SUSE OpenStack Cloud 7 python-cffi Affected
SUSE OpenStack Cloud 7 python-cryptography Affected
SUSE OpenStack Cloud Crowbar 8 python-cffi Released
SUSE OpenStack Cloud Crowbar 8 python-cryptography Released
SUSE OpenStack Cloud Crowbar 9 python-cffi Released
SUSE OpenStack Cloud Crowbar 9 python-cryptography Released
openSUSE Leap 15.4 python-cryptography Released


SUSE Timeline for this CVE

CVE page created: Tue Feb 7 23:00:42 2023
CVE page last modified: Wed Apr 24 19:14:23 2024