CVE-2024-26130: cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override

Published Feb 21, 2024
·
Updated

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if pkcs12.serializekeyandcertificates is called with both a certificate whose public key did not match the provided private key and an encryptionalgorithm with hmachash set (via PrivateFormat.PKCS12.encryptionbuilder().hmachash(...), then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a ValueError is properly raised.

Other sources

cryptography is vulnerable to a denial of service, caused by a NULL pointer dereference in the pkcs12.serializekeyandcertificates process. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.

IBM

If pkcs12.serializekeyandcertificates is called with both:

1. A certificate whose public key did not match the provided private key 2. An encryptionalgorithm with hmachash set (via PrivateFormat.PKCS12.encryptionbuilder().hmachash(...)

Then a NULL pointer dereference would occur, crashing the Python process.

This has been resolved, and now a ValueError is properly raised.

Patched in https://github.com/pyca/cryptography/pull/10423

GitHub

If pkcs12.serializekeyandcertificates is called with both: - A certificate whose public key did not match the provided private key - An encryptionalgorithm with hmachash set (via PrivateFormat.PKCS12.encryptionbuilder().hmachash(...)

Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a ValueError is properly raised.

Affected versions: >= 38.0.0, < 42.0.4

Patched in: https://github.com/pyca/cryptography/pull/10423

References: https://github.com/pyca/cryptography/security/advisories/GHSA-6vqw-3v5j-54x4 https://github.com/pyca/cryptography/pull/10423 https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55

Red Hat

Affected Software

5 affected componentsFixes available
debian/python-cryptography<=38.0.4-3~deb12u1
3.3.2-13.3.2-1+deb11u138.0.4-3+deb12u143.0.0-1
pip/cryptography>=38.0.0<42.0.4
42.0.4
Cryptography.io Cryptography Python>=38.0.0<42.0.4
redhat/cryptography<42.0.4
42.0.4
IBM Concert Software<=1.0.0 - 1.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/python-cryptography to a version that resolves this vulnerability.

    Fixed in 3.3.2-1Fixed in 3.3.2-1+deb11u1Fixed in 38.0.4-3+deb12u1Fixed in 43.0.0-1
  2. Upgrade

    Upgrade pip/cryptography to a version that resolves this vulnerability.

    Fixed in 42.0.4
  3. Upgrade

    Upgrade redhat/cryptography to a version that resolves this vulnerability.

    Fixed in 42.0.4
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 42.0.4Patch GHSA-6vqw-3v5j-54x4
  5. Compensating control

    If you call pkcs12.serialize_key_and_certificates with both (1) a certificate whose public key did not match the provided private key and (2) an encryption_algorithm with hmac_hash set via PrivateFormat.PKCS12.encryption_builder().hmac_hash(...), avoid this combination or ensure the certificate public key matches the provided private key to prevent the NULL pointer dereference/DoS condition (affected in versions >= 38.0.0 and < 42.0.4).

Event History

Feb 21, 2024
CVE Published
via MITRE·04:28 PM
Data Sourced
via MITRE·04:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:04 PM
Mar 4, 2024
Data Sourced
via Launchpad·03:30 PM
Description
Mar 14, 2024
Data Sourced
via Red Hat·10:17 PM
DescriptionSeverityAffected Software
Sep 16, 2024
Data Sourced
via Ubuntu·03:57 PM
RemedyDescriptionSeverityAffected Software
Dec 18, 2024
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-26130?

CVE-2024-26130 has a moderate severity rating as it affects key serialization in cryptographic operations.

2

How do I fix CVE-2024-26130?

To fix CVE-2024-26130, upgrade the cryptography package to version 42.0.4 or later.

3

Which software versions are affected by CVE-2024-26130?

CVE-2024-26130 affects cryptography versions between 38.0.0 and 42.0.4, among others listed in the vulnerability report.

4

What are the potential impacts of CVE-2024-26130?

The potential impacts of CVE-2024-26130 include incorrect key serialization that may lead to vulnerabilities in cryptographic implementations.

5

Is there a specific vendor product impacted by CVE-2024-26130?

Yes, IBM's Storage Defender - Resiliency Service versions up to 2.0.9 are impacted by CVE-2024-26130.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203