[Bug 297639] security/py-pyopenssl: upgrade to 26.2.0,1 broke TLS listener
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 06 Oct 2026 07:45:04 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297639
Vladimir Bychik <vladimir.bychik.dev@gmail.com> changed:
What |Removed |Added
----------------------------------------------------------------------------
CC| |python@FreeBSD.org,
| |vladimir.bychik.dev@gmail.c
| |om
--- Comment #1 from Vladimir Bychik <vladimir.bychik.dev@gmail.com> ---
This is not a pyOpenSSL bug. pyOpenSSL 26.2.0 made it an error to call mutating
methods on an SSL.Context after it has been used to create a Connection
(deprecated with a warning since 25.1). Twisted 25.5.0 does exactly that in
twisted/protocols/tls.py (_setAcceptableProtocols() on connection.get_context()
for IProtocolNegotiationFactory wrapped factories), so every TLS handshake on
an ALPN-capable listener (e.g. Synapse's 8448) raises ValueError and the
connection is dropped, hence the "unexpected eof".
Fixed upstream in Twisted 26.4.0
(https://github.com/twisted/twisted/issues/12500), which also fixes
CVE-2026-42304. devel/py-twisted is still at 25.5.0, so the proper fix is
updating devel/py-twisted to >= 26.4.0; I've filed bug 299174 for that.
Until then, either keep security/py-pyopenssl < 26.2.0, or locally patch tls.py
to catch the ValueError around _setAcceptableProtocols() (this disables ALPN,
falling back to HTTP/1.1).
--
You are receiving this mail because:
You are on the CC list for the bug.