Critical pyOpenSSL Vulnerabilities Affect Ubuntu Users

Critical pyOpenSSL Vulnerabilities Affect Ubuntu Users

First seen 23 Mar 2026, 20:30 UTC UbuntuLinuxsecurity 93% similarity 70.5

Article Content

Browse articles
ThreatCluster

Two vulnerabilities were discovered in pyOpenSSL, affecting Ubuntu 24.04 LTS and 25.10. CVE-2026-27448 allows connections to be accepted after an exception in the tlsext_servername callback, contrary to expectations. CVE-2026-27459 involves improper handling of DTLS cookie generation, where attackers can exploit cookie values over 256 bytes to crash pyOpenSSL, leading to denial of service or potential arbitrary code execution. Both issues were published on 2026-03-17. The vulnerabilities primarily impact Ubuntu users, particularly those on the specified versions. A standard system update is recommended to mitigate these vulnerabilities. Ubuntu Pro offers extended security coverage for affected packages. Users are urged to update their systems to the latest package versions to ensure security.

Key Points: • CVE-2026-27448 and CVE-2026-27459 affect Ubuntu 24.04 LTS and 25.10. • Exploiting these vulnerabilities can lead to denial of service or arbitrary code execution. • Users should update to the latest package versions to mitigate risks.

ThreatCluster AI

Timeline

2026-03-17
CVE-2026-27448 and CVE-2026-27459 published
2026-03-23
Ubuntu releases advisory for pyOpenSSL vulnerabilities

Community

Browse all →