Bug 2544138 (CVE-2026-19445) - CVE-2026-19445 python: Use-after-free of a server-side SSLContext when sni_callback switches contexts
Summary: CVE-2026-19445 python: Use-after-free of a server-side SSLContext when sni_ca...
Keywords:
Status: NEW
Alias: CVE-2026-19445
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2545931 2545932 2545933 2545936 2545938 2545939 2545940 2545941 2545935 2545937
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-30 16:47 UTC by OSIDB Bzimport
Modified: 2026-10-05 15:17 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-30 16:47:20 UTC
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certificate per server
name) and nothing else keeps the original ssl.SSLContext alive. Typical
cases are servers that create an SSLContext per connection or replace it
while connections are open; servers that wrap their listening socket with
it are not affected.


Mitigation: keep a reference to every SSLContext that sets sni_callback for
the lifetime of the server. TLS clients are not affected.


Note You need to log in before you can comment on or make changes to this bug.