Out-of-bounds read in python-cryptography - CVE-2026-39892

 

Out-of-bounds read in python-cryptography - CVE-2026-39892

Published: April 8, 2026 / Updated: May 12, 2026


Vulnerability identifier: #VU125339
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-39892
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to out-of-bounds read in Python buffer-accepting APIs when processing a non-contiguous buffer. A local user can pass a specially crafted non-contiguous buffer to cause a denial of service.

The issue can read past the end of the buffer on Python versions later than 3.11.


Affected software

python-cryptography
Python for Scientific Computing
IBM Cloud Pak for Data System
z/Transaction Processing Facility ( z/TPF)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Object Storage Systems
Storage Sentinel Anomaly Scan Engine
DataStage on Cloud Pak for Data
SOAR QRadar Plugin App
Maximo Application Suite - Predict Component
Maximo Application Suite - Visual Inspection Component
Maximo Application Suite Ai Service
QRadar App SDK
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Maximo Scheduler Optimizer
Fedora
python-cryptography

How to mitigate CVE-2026-39892

Install security update from vendor's website.

python-cryptography - update to 46.0.7
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4
Python for Scientific Computing - update to 4.3.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
DataStage on Cloud Pak for Data - addressed in versions 5.3.1 patch 6, 5.4 patch 5
SOAR QRadar Plugin App - update to 5.6.5
Maximo Application Suite - Predict Component - addressed in versions 8.8.15, 8.9.17, 9.0.14, 9.1.7
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.20, 9.1.18
Maximo Application Suite Ai Service - update to 9.1.16
QRadar App SDK - update to 2.2.5
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.91, 3.20.1.84
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4.2
watsonx Assistant Cartridge - update to 5.4.2
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
python-cryptography - addressed in versions 46.0.7-1.fc43, 46.0.7-1.fc44

External References

Related Security Bulletins