CVE-2026-9669
published 2026-06-08CVE-2026-9669: bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor…
PriorityP345high8.2CVSS 4.0
AVNACHATPPRNUINVCNVINVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.42%
34.2th percentile
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| python36_3.6 | python36 | — | — |
| python_software_foundation | cpython | < 3.13.14 | 3.13.14 |
| python_software_foundation | cpython | >= 3.14.0 < 3.14.6 | 3.14.6 |
| python_software_foundation | cpython | >= 3.15.0a1 < 3.15.0b3 | 3.15.0b3 |
| ubuntu | python3.10 | — | — |
| ubuntu | python3.12 | — | — |
| ubuntu | python3.14 | — | — |
CVSS provenance
nvdv4.08.2HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.2HIGH
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Python CPython up to 3.15.x bz2.BZ2Decompressor stack-based overflow (ID 150599 / Nessus ID 325428)
vuldb·2026-07-08·CVSS 8.2
CVE-2026-9669 [HIGH] Python CPython up to 3.15.x bz2.BZ2Decompressor stack-based overflow (ID 150599 / Nessus ID 325428)
A vulnerability described as critical has been identified in Python CPython up to 3.15.x. Affected by this issue is the function bz2.BZ2Decompressor. Executing a manipulation can lead to stack-based buffer overflow.
The identification of this vulnerability is CVE-2026-9669. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
bz2.BZ2Decompressor objects could be reused after a decompression error.
ghsa_unreviewed·2026-06-09
CVE-2026-9669 [HIGH] CWE-121 bz2.BZ2Decompressor objects could be reused after a decompression error.
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 3.3
CVE-2026-9669 [LOW] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly normalized paths in the tarfile
module. An attacker could possibly use this issue to bypass path
restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2025-13462)
It was discovered that Python's HTMLParser incorrectly handled certain
malformed HTML input. An attacker could possibly use this issue to cause
Python to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534)
It was discovered that Python's email module incorrectly quoted newlines
in headers. An attacker could possibly use this issue to inject arbitrary
email headers. This issue only affected Ubuntu 22.04 L
Red Hat
python: Python: Denial of Service via out-of-bounds write in BZ2 decompression
vendor_redhat·2026-06-08·CVSS 8.2
CVE-2026-9669 [HIGH] CWE-787 python: Python: Denial of Service via out-of-bounds write in BZ2 decompression
python: Python: Denial of Service via out-of-bounds write in BZ2 decompression
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.
A flaw was found in Python's `bz2.BZ2Decompressor` component. An attacker could provide specially crafted input that, when processed by an application reusing a decompressor object after an error, could lead to out-of-bounds writes in memory. This memory corruption could cause the application to crash, resulting in a Denial of Service (DoS).
Statement: This M
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9669 mercurial: Python: Denial of Service via out-of-bounds write in BZ2 decompression [fedora-all]
bugzilla·2026-06-15·CVSS 8.2
CVE-2026-9669 [HIGH] CVE-2026-9669 mercurial: Python: Denial of Service via out-of-bounds write in BZ2 decompression [fedora-all]
CVE-2026-9669 mercurial: Python: Denial of Service via out-of-bounds write in BZ2 decompression [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
What is the value of this report? What should who do about that?
Bugzilla
CVE-2026-9669 mercurial: Python: Denial of Service via out-of-bounds write in BZ2 decompression [epel-all]
bugzilla·2026-06-15·CVSS 8.2
CVE-2026-9669 [HIGH] CVE-2026-9669 mercurial: Python: Denial of Service via out-of-bounds write in BZ2 decompression [epel-all]
CVE-2026-9669 mercurial: Python: Denial of Service via out-of-bounds write in BZ2 decompression [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-9669 python: Python: Denial of Service via out-of-bounds write in BZ2 decompression
bugzilla·2026-06-08·CVSS 8.2
CVE-2026-9669 [HIGH] CVE-2026-9669 python: Python: Denial of Service via out-of-bounds write in BZ2 decompression
CVE-2026-9669 python: Python: Denial of Service via out-of-bounds write in BZ2 decompression
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.
https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036ehttps://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6fhttps://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702dhttps://github.com/python/cpython/issues/150599https://github.com/python/cpython/pull/150600https://mail.python.org/archives/list/[email protected]/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/http://www.openwall.com/lists/oss-security/2026/06/08/17
2026-06-08
Published