CVE-2020-36242
published 2021-02-07CVE-2020-36242: In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer…
PriorityP352critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
6.72%
93.2th percentile
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cryptography.io | cryptography | < 3.3.2 | 3.3.2 |
| cryptography.io | cryptography | >= 3.1 < 3.3.2 | 3.3.2 |
| debian | python-cryptography | < python-cryptography 3.3.2-1 (bookworm) | python-cryptography 3.3.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cm1_python-cryptography_3.3.2-1_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_msrc9.1CRITICAL
vendor_oracle9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
Oracle
Oracle Oracle MySQL Risk Matrix: Shell: Core Client (cryptography) — CVE-2020-36242
vendor_oracle·2023-01-15·CVSS 9.1
CVE-2020-36242 [CRITICAL] Oracle Oracle MySQL Risk Matrix: Shell: Core Client (cryptography) — CVE-2020-36242
Oracle Oracle MySQL Risk Matrix: Shell: Core Client (cryptography) vulnerability
CVE: CVE-2020-36242
CVSS: 9.1
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Risk Matrix: OC-CNE (python-cryptography) — CVE-2020-36242
vendor_oracle·2022-04-15·CVSS 9.1
CVE-2020-36242 [CRITICAL] Oracle Oracle Communications Risk Matrix: OC-CNE (python-cryptography) — CVE-2020-36242
Oracle Oracle Communications Risk Matrix: OC-CNE (python-cryptography) vulnerability
CVE: CVE-2020-36242
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Microsoft
In the cryptography package before 3.3.2 for Python certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow as demonstrated b
vendor_msrc·2021-02-09·CVSS 9.1
CVE-2020-36242 [CRITICAL] CWE-787 In the cryptography package before 3.3.2 for Python certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow as demonstrated b
In the cryptography package before 3.3.2 for Python certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow as demonstrated by the Fernet class.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified,
Red Hat
python-cryptography: Large inputs for symmetric encryption can trigger integer overflow leading to buffer overflow
vendor_redhat·2020-12-09·CVSS 9.1
CVE-2020-36242 [CRITICAL] CWE-190 python-cryptography: Large inputs for symmetric encryption can trigger integer overflow leading to buffer overflow
python-cryptography: Large inputs for symmetric encryption can trigger integer overflow leading to buffer overflow
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
A buffer-overflow flaw was found in the python-cryptography package. In certain sequences of ``update()`` calls when symmetrically encrypting very large payloads (>2GB) could result in an integer overflow, leading to buffer overflows. Note: This fix is a workaround for the OpenSSL CVE-2021-23840 flaw. Source: pyca/cryptography project
Statement: Triggering this flaw on in versions of python-cryptography as shipped with Red Hat Enterprise Linux 8 BaseOS, Ap
Debian
CVE-2020-36242: python-cryptography - In the cryptography package before 3.3.2 for Python, certain sequences of update...
vendor_debian·2020·CVSS 9.1
CVE-2020-36242 [CRITICAL] CVE-2020-36242: python-cryptography - In the cryptography package before 3.3.2 for Python, certain sequences of update...
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
Scope: local
bookworm: resolved (fixed in 3.3.2-1)
bullseye: resolved (fixed in 3.3.2-1)
forky: resolved (fixed in 3.3.2-1)
sid: resolved (fixed in 3.3.2-1)
trixie: resolved (fixed in 3.3.2-1)
GHSA
PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
ghsa·2021-02-10
CVE-2020-36242 [HIGH] CWE-190 PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. When certain sequences of `update()` calls with large values (multiple GBs) for symetric encryption or decryption occur, it's possible for an integer overflow to happen, leading to mishandling of buffers. This is patched in version 3.3.2 and newer.
OSV
PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
osv·2021-02-10
CVE-2020-36242 [HIGH] PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. When certain sequences of `update()` calls with large values (multiple GBs) for symetric encryption or decryption occur, it's possible for an integer overflow to happen, leading to mishandling of buffers. This is patched in version 3.3.2 and newer.
OSV
CVE-2020-36242: In the cryptography package before 3
osv·2021-02-07·CVSS 9.1
CVE-2020-36242 [CRITICAL] CVE-2020-36242: In the cryptography package before 3
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
No detection rules found.
No public exploits indexed.
https://github.com/pyca/cryptography/blob/master/CHANGELOG.rsthttps://github.com/pyca/cryptography/compare/3.3.1...3.3.2https://github.com/pyca/cryptography/issues/5615https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/pyca/cryptography/blob/master/CHANGELOG.rsthttps://github.com/pyca/cryptography/compare/3.3.1...3.3.2https://github.com/pyca/cryptography/issues/5615https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-02-07
Published