Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package python-cryptography for
openSUSE:Factory checked in at 2026-08-06 16:18:03
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-cryptography (Old)
and /work/SRC/openSUSE:Factory/.python-cryptography.new.16738 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-cryptography"
Thu Aug 6 16:18:03 2026 rev:114 rq:1369600 version:50.0.0
Changes:
--------
--- /work/SRC/openSUSE:Factory/python-cryptography/python-cryptography.changes
2026-06-16 18:29:08.164855668 +0200
+++
/work/SRC/openSUSE:Factory/.python-cryptography.new.16738/python-cryptography.changes
2026-08-06 16:18:07.431904416 +0200
@@ -1,0 +2,78 @@
+Tue Aug 4 21:28:10 UTC 2026 - Dirk Müller <[email protected]>
+
+- update to 50.0.0 (bsc#1273551, CVE-2026-69247):
+ * SECURITY ISSUE: :func:`~cryptography.hazmat.primitives.serial
+ ization.pkcs7.pkcs7_decrypt_der` and its PEM and S/MIME
+ variants no longer expose distinguishable errors or timing
+ when unwrapping a RecipientInfo's encryptedKey, which could
+ act as a Bleichenbacher oracle for callers that decrypt
+ untrusted messages. A random key is now substituted on
+ failure, as described in RFC 3218. Credit to @X1AOxiang for
+ reporting the issue
+ * Deprecated Diffie-Hellman key exchange over finite fields
+ (FFDH). Everything FFDH is deprecated, including the types in
+ cryptography.hazmat.primitives.asymmetric.dh and loading FFDH
+ keys or parameters with the key loading APIs. Users should
+ migrate to a more modern key exchange algorithm.
+ * Added xof() class methods to
+ :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
+ :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for
+ constructing algorithm instances configured for use with
+ :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
+ * The :mod:`X.509 verification
+ <cryptography.x509.verification>` APIs are now considered
+ stable and are subject to our API stability policy.
+ * Added the :doc:`/cobblestone` recipe, an implementation of
+ the Cobblestone-128 and Cobblestone-256 instantiations of the
+ C2SP chunked-encryption specification for streaming
+ authenticated encryption of large messages.
+ * Parsing a Signed Certificate Timestamp list now rejects
+ encodings that carry trailing bytes after the list or after
+ an individual SCT, instead of silently ignoring them.
+ * Added support for using :class:`~cryptography.x509.Name` as a
+ field type in the :doc:`/hazmat/asn1/index` module.
+ * Loading a public key or an EC private key now rejects DER
+ where the subjectPublicKey (or EC publicKey) BIT STRING
+ declares a non-zero number of unused bits, instead of
+ silently ignoring it.
+ * Parsing a CRL entry's InvalidityDate extension now rejects a
+ GeneralizedTime that carries fractional seconds or another
+ non-DER form, matching the strict encoding already required
+ for every other X.509 time field.
+ * :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
+ :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now
+ reject a request or response whose version field is not v1,
+ the only version defined by RFC 6960, matching the version
+ validation already performed when loading certificates, CSRs
+ and CRLs.
+ * :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is
+ now supported when building against AWS-LC.
+ * HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now
+ supported when building against AWS-LC.
+ * Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is
+ now supported when building against AWS-LC.
+ * :func:`~cryptography.hazmat.primitives.serialization.load_der
+ _public_key` and :func:`~cryptography.hazmat.primitives.seria
+ lization.load_pem_public_key` now reject Diffie-Hellman
+ public keys whose modulus is smaller than 512 bits, matching
+ the minimum already enforced when loading DH private keys and
+ when constructing :class:`~cryptography.hazmat.primitives.asy
+ mmetric.dh.DHParameterNumbers`.
+ * Added :class:`~cryptography.hazmat.primitives.asymmetric.mlds
+ a.MLDSAMuHasher` for incrementally computing the ML-DSA mu
+ (message representative) used by the external-mu signing and
+ verification APIs.
+ * The builtin
+ :class:`~cryptography.hazmat.primitives.hashes.HashAlgorithm`
+ classes and the classes in
+ :mod:`~cryptography.hazmat.primitives.asymmetric.padding` can
+ now be compared with ==.
+ * :class:`~cryptography.x509.CertificateBuilder` now supports
+ creating unsigned certificates (RFC 9925) with the
+ create_unsigned method.
+ * The :mod:`X.509 verification
+ <cryptography.x509.verification>` APIs now permit ML-DSA-44,
+ ML-DSA-65, and ML-DSA-87 (RFC 9881) public keys and
+ signatures by default.
+
+-------------------------------------------------------------------
Old:
----
cryptography-49.0.0.tar.gz
New:
----
cryptography-50.0.0.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ python-cryptography.spec ++++++
--- /var/tmp/diff_new_pack.mgwHMd/_old 2026-08-06 16:18:08.571944312 +0200
+++ /var/tmp/diff_new_pack.mgwHMd/_new 2026-08-06 16:18:08.575944452 +0200
@@ -28,7 +28,7 @@
%{?sle15_python_module_pythons}
Name: python-cryptography%{psuffix}
# ALWAYS KEEP IN SYNC WITH python-cryptography-vectors!
-Version: 49.0.0
+Version: 50.0.0
Release: 0
Summary: Python library which exposes cryptographic recipes and
primitives
License: Apache-2.0 OR BSD-3-Clause
++++++ cryptography-49.0.0.tar.gz -> cryptography-50.0.0.tar.gz ++++++
++++ 27383 lines of diff (skipped)
++++++ vendor.tar.zst ++++++
++++ 827023 lines of diff (skipped)