Alerts This Week
Warning Icon 1 1,009
Alerts This Week
Warning Icon 1 1,009

Ubuntu 25.10 pyOpenSSL Critical Fix for Denial of Service CVE-2026-27459

ubuntu
Calendar Grey March 23, 2026
Dist Ubuntu Esm H88
Several issues fixed in pyOpenSSL for different Ubuntu versions to prevent service disruptions. Stay updated now!
Several security issues were fixed in pyOpenSSL.

Summary

Several security issues were fixed in pyOpenSSL.

Software Description:

- pyopenssl: Python wrapper around the OpenSSL library

Details:

It was discovered that pyOpenSSL incorrectly handled exceptions in the

tlsext_servername callback. This could result in connections being

accepted after an exception, contrary to expectations. (CVE-2026-27448)

It was discovered that pyOpenSSL incorrectly handled the DTLS cookie

generation callback. If a callback provided cookie values greater than 256

bytes, an attacker could use this issue to cause pyOpenSSL to crash,

resulting in a denial of service, or possibly execute arbitrary code. This

issue only affected Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2026-27459)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  python3-openssl                 25.0.0-1ubuntu0.1

Ubuntu 24.04 LTS
  python3-openssl                 23.2.0-1ubuntu0.1

Ubuntu 22.04 LTS
  python3-openssl                 21.0.0-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8115-1

CVE-2026-27448, CVE-2026-27459

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8115-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here