Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package python-cryptography for 
openSUSE:Factory checked in at 2026-08-06 16:18:03
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-cryptography (Old)
 and      /work/SRC/openSUSE:Factory/.python-cryptography.new.16738 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "python-cryptography"

Thu Aug  6 16:18:03 2026 rev:114 rq:1369600 version:50.0.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/python-cryptography/python-cryptography.changes  
2026-06-16 18:29:08.164855668 +0200
+++ 
/work/SRC/openSUSE:Factory/.python-cryptography.new.16738/python-cryptography.changes
       2026-08-06 16:18:07.431904416 +0200
@@ -1,0 +2,78 @@
+Tue Aug  4 21:28:10 UTC 2026 - Dirk Müller <[email protected]>
+
+- update to 50.0.0 (bsc#1273551, CVE-2026-69247):
+  * SECURITY ISSUE: :func:`~cryptography.hazmat.primitives.serial
+    ization.pkcs7.pkcs7_decrypt_der` and its PEM and S/MIME
+    variants no longer expose distinguishable errors or timing
+    when unwrapping a RecipientInfo's encryptedKey, which could
+    act as a Bleichenbacher oracle for callers that decrypt
+    untrusted messages. A random key is now substituted on
+    failure, as described in RFC 3218. Credit to @X1AOxiang for
+    reporting the issue
+  * Deprecated Diffie-Hellman key exchange over finite fields
+    (FFDH). Everything FFDH is deprecated, including the types in
+    cryptography.hazmat.primitives.asymmetric.dh and loading FFDH
+    keys or parameters with the key loading APIs. Users should
+    migrate to a more modern key exchange algorithm.
+  * Added xof() class methods to
+    :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
+    :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for
+    constructing algorithm instances configured for use with
+    :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
+  * The :mod:`X.509 verification
+    <cryptography.x509.verification>` APIs are now considered
+    stable and are subject to our API stability policy.
+  * Added the :doc:`/cobblestone` recipe, an implementation of
+    the Cobblestone-128 and Cobblestone-256 instantiations of the
+    C2SP chunked-encryption specification for streaming
+    authenticated encryption of large messages.
+  * Parsing a Signed Certificate Timestamp list now rejects
+    encodings that carry trailing bytes after the list or after
+    an individual SCT, instead of silently ignoring them.
+  * Added support for using :class:`~cryptography.x509.Name` as a
+    field type in the :doc:`/hazmat/asn1/index` module.
+  * Loading a public key or an EC private key now rejects DER
+    where the subjectPublicKey (or EC publicKey) BIT STRING
+    declares a non-zero number of unused bits, instead of
+    silently ignoring it.
+  * Parsing a CRL entry's InvalidityDate extension now rejects a
+    GeneralizedTime that carries fractional seconds or another
+    non-DER form, matching the strict encoding already required
+    for every other X.509 time field.
+  * :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
+    :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now
+    reject a request or response whose version field is not v1,
+    the only version defined by RFC 6960, matching the version
+    validation already performed when loading certificates, CSRs
+    and CRLs.
+  * :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is
+    now supported when building against AWS-LC.
+  * HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now
+    supported when building against AWS-LC.
+  * Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is
+    now supported when building against AWS-LC.
+  * :func:`~cryptography.hazmat.primitives.serialization.load_der
+    _public_key` and :func:`~cryptography.hazmat.primitives.seria
+    lization.load_pem_public_key` now reject Diffie-Hellman
+    public keys whose modulus is smaller than 512 bits, matching
+    the minimum already enforced when loading DH private keys and
+    when constructing :class:`~cryptography.hazmat.primitives.asy
+    mmetric.dh.DHParameterNumbers`.
+  * Added :class:`~cryptography.hazmat.primitives.asymmetric.mlds
+    a.MLDSAMuHasher` for incrementally computing the ML-DSA mu
+    (message representative) used by the external-mu signing and
+    verification APIs.
+  * The builtin
+    :class:`~cryptography.hazmat.primitives.hashes.HashAlgorithm`
+    classes and the classes in
+    :mod:`~cryptography.hazmat.primitives.asymmetric.padding` can
+    now be compared with ==.
+  * :class:`~cryptography.x509.CertificateBuilder` now supports
+    creating unsigned certificates (RFC 9925) with the
+    create_unsigned method.
+  * The :mod:`X.509 verification
+    <cryptography.x509.verification>` APIs now permit ML-DSA-44,
+    ML-DSA-65, and ML-DSA-87 (RFC 9881) public keys and
+    signatures by default.
+
+-------------------------------------------------------------------

Old:
----
  cryptography-49.0.0.tar.gz

New:
----
  cryptography-50.0.0.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ python-cryptography.spec ++++++
--- /var/tmp/diff_new_pack.mgwHMd/_old  2026-08-06 16:18:08.571944312 +0200
+++ /var/tmp/diff_new_pack.mgwHMd/_new  2026-08-06 16:18:08.575944452 +0200
@@ -28,7 +28,7 @@
 %{?sle15_python_module_pythons}
 Name:           python-cryptography%{psuffix}
 # ALWAYS KEEP IN SYNC WITH python-cryptography-vectors!
-Version:        49.0.0
+Version:        50.0.0
 Release:        0
 Summary:        Python library which exposes cryptographic recipes and 
primitives
 License:        Apache-2.0 OR BSD-3-Clause

++++++ cryptography-49.0.0.tar.gz -> cryptography-50.0.0.tar.gz ++++++
++++ 27383 lines of diff (skipped)

++++++ vendor.tar.zst ++++++
++++ 827023 lines of diff (skipped)

Reply via email to