CVE-2020-36242
9.1
CRITICAL · CVSS 3.1 · EPSS 6.7% (pctl 94)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 6.72% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-190 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-02-07 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| cryptography.io | cryptography |
| fedoraproject | fedora |
| oracle | communications cloud native core network function cloud native environment |
References
- https://github.com/pyca/cryptography/blob/master/CHANGELOG.rst
- https://github.com/pyca/cryptography/compare/3.3.1...3.3.2
- https://github.com/pyca/cryptography/issues/5615
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://github.com/pyca/cryptography/blob/master/CHANGELOG.rst
- https://github.com/pyca/cryptography/compare/3.3.1...3.3.2
- https://github.com/pyca/cryptography/issues/5615
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
→ the Explorer · watch your stack · NVD