From d41a814759a9fb49584ca8ab3f7295de49a85aa0 Mon Sep 17 00:00:00 2001 From: Alex Gaynor Date: Mon, 16 Feb 2026 21:04:37 -0500 Subject: [PATCH] Handle exceptions in set_tlsext_servername_callback callbacks (#1478) When the servername callback raises an exception, call sys.excepthook with the exception info and return SSL_TLSEXT_ERR_ALERT_FATAL to abort the handshake. Previously, exceptions would propagate uncaught through the CFFI callback boundary. https://claude.ai/code/session_01P7y1XmWkdtC5UcmZwGDvGi Co-authored-by: Claude Upstream: https://github.com/pyca/pyopenssl/commit/d41a814759a9fb49584ca8ab3f7295de49a85aa0 CVE: CVE-2026-27448 [thomas: backported, stripped tests and changelog] Signed-off-by: Thomas Perale --- src/OpenSSL/SSL.py | 7 ++++++- 1 files changed, 7 insertions(+) diff --git a/src/OpenSSL/SSL.py b/src/OpenSSL/SSL.py index 4db5240..a6263c4 100644 --- a/src/OpenSSL/SSL.py +++ b/src/OpenSSL/SSL.py @@ -2,6 +2,7 @@ import os import socket +import sys import typing import warnings from collections.abc import Sequence @@ -1686,7 +1687,11 @@ class Context: @wraps(callback) def wrapper(ssl, alert, arg): # type: ignore[no-untyped-def] - callback(Connection._reverse_mapping[ssl]) + try: + callback(Connection._reverse_mapping[ssl]) + except Exception: + sys.excepthook(*sys.exc_info()) + return _lib.SSL_TLSEXT_ERR_ALERT_FATAL return 0 self._tlsext_servername_callback = _ffi.callback( -- 2.43.0