PT-2026-47453 · Python+1 · Python+1

·

CVE-2026-9669

·

Published

2026-06-08

·

Updated

2026-07-23

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Python (affected versions not specified)
Description bz2.BZ2Decompressor objects can be reused following a decompression error. If an application catches the resulting OSError and attempts to retry using the same decompressor, specially crafted input may cause the decompressor to resume from an invalid internal state. This leads to out-of-bounds writes to a stack buffer, which can result in a process crash when processing untrusted data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-LIBPYTHON-2026-9669
BIT-PYTHON-2026-9669
BIT-PYTHON-MIN-2026-9669
CVE-2026-9669
ECHO-19F0-B298-0F29
OESA-2026-2694
OESA-2026-2695
OPENSUSE-SU-2026:11181-1
PSF-2026-27
USN-8509-1

Affected Products

Linuxmint
Python