Bug 2448503 (CVE-2026-27459) - CVE-2026-27459 pyOpenSSL: DTLS cookie callback buffer overflow
Summary: CVE-2026-27459 pyOpenSSL: DTLS cookie callback buffer overflow
Keywords:
Status: NEW
Alias: CVE-2026-27459
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2448655 2448652
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-18 00:02 UTC by OSIDB Bzimport
Modified: 2026-05-04 14:16 UTC (History)
54 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:10754 0 None None None 2026-04-27 10:13:33 UTC
Red Hat Product Errata RHSA-2026:13508 0 None None None 2026-05-04 13:58:57 UTC
Red Hat Product Errata RHSA-2026:13512 0 None None None 2026-05-04 14:16:07 UTC

Description OSIDB Bzimport 2026-03-18 00:02:08 UTC
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.

Comment 2 errata-xmlrpc 2026-04-27 10:13:29 UTC
This issue has been addressed in the following products:

  RHUI 4 for RHEL 8

Via RHSA-2026:10754 https://access.redhat.com/errata/RHSA-2026:10754

Comment 3 errata-xmlrpc 2026-05-04 13:58:53 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 10
  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:13508 https://access.redhat.com/errata/RHSA-2026:13508

Comment 4 errata-xmlrpc 2026-05-04 14:16:03 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:13512 https://access.redhat.com/errata/RHSA-2026:13512


Note You need to log in before you can comment on or make changes to this bug.