Updated: 2025-08-20 00:14:05.323893
Description:
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | 0.0 | |
| CVSS Version 3.x | MEDIUM | 5.9 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| Debian 10 | python | 3.6 | 5.9 | MEDIUM | Already Fixed | 2025-09-09 19:25:59 | ||
| Debian 10 | python | 2.7 | 5.9 | MEDIUM | Released | CLSA-2025:1760705864 | 2025-10-17 14:04:42 | |
| Debian 11 | python | 2.7 | 5.9 | MEDIUM | Released | CLSA-2025:1760705964 | 2025-10-17 14:04:40 | |
| Debian 11 | python | 3.6 | 5.9 | MEDIUM | Already Fixed | 2025-09-09 19:25:59 | ||
| Debian 12 | python | 3.9 | 5.9 | MEDIUM | Not Vulnerable | 2025-12-11 07:44:39 | ||
| Debian 12 | python | 3.7 | 5.9 | MEDIUM | Not Vulnerable | 2025-12-11 07:45:45 | ||
| Debian 12 | python | 3.6 | 5.9 | MEDIUM | Already Fixed | 2025-09-09 19:25:58 | ||
| Debian 12 | python | 2.7 | 5.9 | MEDIUM | Released | CLSA-2025:1760706062 | 2025-10-17 14:04:39 | |
| Debian 12 | python | 3.8 | 5.9 | MEDIUM | Not Vulnerable | 2025-12-11 07:45:45 | ||
| Debian 13 | python | 3.9 | 5.9 | MEDIUM | Not Vulnerable | 2025-12-11 07:44:38 |