Follow @Openwall on Twitter for new release announcements and other news
[<prev] [day] [month] [year] [list]
Message-ID: <d65e5089-a707-458e-8fef-346a3650564f@oracle.com>
Date: Wed, 30 Sep 2026 09:58:23 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Subject: CPython [CVE-2026-19445] Use-after-free of a
 server-side SSLContext when sni_callback switches contexts




-------- Forwarded Message --------
Subject: 	[Security-announce][CVE-2026-19445] Use-after-free of a server-side 
SSLContext when sni_callback switches contexts
Date: 	Wed, 30 Sep 2026 16:10:08 +0000
From: 	Seth Larson <seth@...hon.org>
Reply-To: 	security-sig@...hon.org
To: 	security-announce@...hon.org

There is a CRITICAL severity vulnerability affecting CPython.

A remote, unauthenticated TLS client can make a server crash or call through a 
freed pointer if its sni_callback assigns a different context to 
SSLSocket.context (the documented way to select a certificate per server name) 
and nothing else keeps the original ssl.SSLContext alive. Typical cases are 
servers that create an SSLContext per connection or replace it while connections 
are open; servers that wrap their listening socket with it are not affected.

Mitigation: keep a reference to every SSLContext that sets sni_callback for the 
lifetime of the server. TLS clients are not affected.

Please see the linked CVE ID for the latest information on affected versions:

* https://www.cve.org/CVERecord?id=CVE-2026-19445
* https://github.com/python/cpython/pull/158504

_______________________________________________
Security-announce mailing list -- security-announce@...hon.org
https://mail.python.org/mailman3//lists/security-announce.python.org

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.