Advisories ยป MGASA-2026-0074

Updated python-openssl packages fix security vulnerabilities

Publication date: 31 Mar 2026
Modification date: 31 Mar 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-27448 , CVE-2026-27459

Description

pyOpenSSL allows TLS connection bypass via unhandled callback exception
in set_tlsext_servername_callback. (CVE-2026-27448)
pyOpenSSL DTLS cookie callback buffer overflow. (CVE-2026-27459)
                

References

SRPMS

9/core