Out-of-bounds read in python-cryptography - CVE-2026-39892
Published: April 8, 2026 / Updated: May 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds read in Python buffer-accepting APIs when processing a non-contiguous buffer. A local user can pass a specially crafted non-contiguous buffer to cause a denial of service.
The issue can read past the end of the buffer on Python versions later than 3.11.
Affected software
Python for Scientific Computing
IBM Cloud Pak for Data System
z/Transaction Processing Facility ( z/TPF)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Object Storage Systems
Storage Sentinel Anomaly Scan Engine
DataStage on Cloud Pak for Data
SOAR QRadar Plugin App
Maximo Application Suite - Predict Component
Maximo Application Suite - Visual Inspection Component
Maximo Application Suite Ai Service
QRadar App SDK
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Maximo Scheduler Optimizer
Fedora
python-cryptography
How to mitigate CVE-2026-39892
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4
Python for Scientific Computing - update to 4.3.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
DataStage on Cloud Pak for Data - addressed in versions 5.3.1 patch 6, 5.4 patch 5
SOAR QRadar Plugin App - update to 5.6.5
Maximo Application Suite - Predict Component - addressed in versions 8.8.15, 8.9.17, 9.0.14, 9.1.7
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.20, 9.1.18
Maximo Application Suite Ai Service - update to 9.1.16
QRadar App SDK - update to 2.2.5
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.91, 3.20.1.84
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4.2
watsonx Assistant Cartridge - update to 5.4.2
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
python-cryptography - addressed in versions 46.0.7-1.fc43, 46.0.7-1.fc44
External References
Related Security Bulletins
- Out-of-bounds read in python-cryptography
- Fedora 44 update for python-cryptography
- Fedora 43 update for python-cryptography
- IBM Maximo Application Suite - Predict Component update for cryptography
- IBM Maximo Scheduler Optimizer update for cryptography
- IBM Watson Discovery Cartridge update for cryptography
- IBM z/Transaction Processing Facility update for cryptography
- Multiple vulnerabilities in IBM Cloud Pak for Data System
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Multiple vulnerabilities in IBM Maximo AI Service
- Splunk Python for Scientific Computing update for third-party components
- Multiple vulnerabilities in IBM QRadar App SDK
- Multiple vulnerabilities in IBM Cloud Object Storage System
- Multiple vulnerabilities in IBM Maximo Application Suite - Visual Inspection Component
- IBM SOAR QRadar Plugin App update for cryptography
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for cryptography
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data