bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
Published Jun 8, 2026
8.2
HIGHCVSS 4.0
EPSS 0.60%
Description
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.
Affected products
-
- Version 0StatusaffectedConstraints<3.10.21
- Version 3.11.0StatusaffectedConstraints<3.11.16
- Version 3.12.0StatusaffectedConstraints<3.12.14
- Version 3.13.0StatusaffectedConstraints<3.13.14
- Version 3.14.0StatusaffectedConstraints<3.14.6
- Version 3.15.0a1StatusaffectedConstraints<3.15.0b3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Python Software Foundation | CPython | unaffected |
|
No data.
No data.
Red Hat Hardened Images
python3-10-main-3.10.21-1.3.hum1
Fixed · RHSA-2026:68132
Red Hat Hardened Images
python3-11-main-3.11.16-1.4.hum1
Fixed · RHSA-2026:68135
Red Hat Hardened Images
python3-12-main-3.12.14-1.3.hum1
Fixed · RHSA-2026:68154
Red Hat Hardened Images
python3-13-main-3.13.15-1.3.hum1
Fixed · RHSA-2026:68309
Red Hat Hardened Images
python3-14-main-3.14.7-1.2.hum1
Fixed · RHSA-2026:67572
Red Hat Enterprise Linux 8
python36
Fix deferred
Red Hat Hardened Images
hi/python
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | python3-10-main-3.10.21-1.3.hum1 | Fixed | RHSA-2026:68132 |
| Red Hat Hardened Images | python3-11-main-3.11.16-1.4.hum1 | Fixed | RHSA-2026:68135 |
| Red Hat Hardened Images | python3-12-main-3.12.14-1.3.hum1 | Fixed | RHSA-2026:68154 |
| Red Hat Hardened Images | python3-13-main-3.13.15-1.3.hum1 | Fixed | RHSA-2026:68309 |
| Red Hat Hardened Images | python3-14-main-3.14.7-1.2.hum1 | Fixed | RHSA-2026:67572 |
| Red Hat Enterprise Linux 8 | python36 | Fix deferred | n/a |
| Red Hat Hardened Images | hi/python | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate-impact flaw in Python's `bz2.BZ2Decompressor` component affects Red Hat Enterprise Linux 8. It allows an attacker to trigger a denial of service by providing specially crafted compressed data. Exploitation requires an application to reuse a `BZ2Decompressor` object after a decompression error, leading to out-of-bounds writes and a crash.
Red Hat mitigation
Applications processing untrusted BZ2 compressed data should avoid reusing `bz2.BZ2Decompressor` objects after a decompression error. Instead, a new `bz2.BZ2Decompressor` instance should be created for each new decompression attempt or after an error occurs. This prevents the decompressor from resuming from an invalid internal state.
References (15)
- http://www.openwall.com/lists/oss-security/2026/06/08/17
- https://access.redhat.com/security/cve/CVE-2026-9669 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2486590 Issue Tracking
- https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6 patch
- https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636 patch
- https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e patch
- https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f patch
- https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79 patch
- https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2 patch
- https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d patch
- https://github.com/python/cpython/issues/150599 issue-tracking
- https://github.com/python/cpython/pull/150600 patch
- https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-9669
- https://www.cve.org/CVERecord?id=CVE-2026-9669
Change history (0)
No recorded changes yet.