Back

HIGH

bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow

Published Jun 8, 2026

Description

bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.

Affected products

Remediation

Red Hat statement

This Moderate-impact flaw in Python's `bz2.BZ2Decompressor` component affects Red Hat Enterprise Linux 8. It allows an attacker to trigger a denial of service by providing specially crafted compressed data. Exploitation requires an application to reuse a `BZ2Decompressor` object after a decompression error, leading to out-of-bounds writes and a crash.

Red Hat mitigation

Applications processing untrusted BZ2 compressed data should avoid reusing `bz2.BZ2Decompressor` objects after a decompression error. Instead, a new `bz2.BZ2Decompressor` instance should be created for each new decompression attempt or after an error occurs. This prevents the decompressor from resuming from an invalid internal state.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PSF
Published Jun 8, 2026
Updated Aug 13, 2026
Reserved May 27, 2026
CISA Vulnrichment
Updated Jun 16, 2026
NVD
Status Awaiting Analysis
Modified Aug 13, 2026
Red Hat
Severity Moderate
Public date Jun 8, 2026