CVE-2020-25659

medium
Published 2020-10-27 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2
VIR risk
5.5

Description

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-25659

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2021:1608

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-25659.html

OS impact

OSVersionStatusFixed in
suse slesaffected
rockylinux rocky8fixed
debian debianbookwormfixed3.2.1-1
debian debianbullseyefixed3.2.1-1
debian debianforkyfixed3.2.1-1
debian debiansidfixed3.2.1-1
debian debiantrixiefixed3.2.1-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIcryptography<3.23.2
python PyPIcryptography<3.2.13.2.1

References

Verify integrity in audit chain (admin only). AS-IS.