High severityNVD Advisory· Published Jun 8, 2026· Updated Jun 10, 2026
CVE-2026-9669
CVE-2026-9669
Description
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9(expand)+ 1 more
- (no CPE)
- (no CPE)
- osv-coords7 versionspkg:apk/chainguard/python-3.13pkg:apk/chainguard/python-3.14pkg:apk/wolfi/python-3.13pkg:apk/wolfi/python-3.14pkg:bitnami/libpythonpkg:bitnami/pythonpkg:bitnami/python-min
< 3.13.14-r0+ 6 more
- (no CPE)range: < 3.13.14-r0
- (no CPE)range: < 3.14.6-r1
- (no CPE)range: < 3.13.14-r0
- (no CPE)range: < 3.14.6-r1
- (no CPE)range: < 3.13.14
- (no CPE)range: < 3.13.14
- (no CPE)range: < 3.13.14
Patches
Vulnerability mechanics
References
8- www.openwall.com/lists/oss-security/2026/06/08/17nvd
- github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6nvd
- github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036envd
- github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6fnvd
- github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702dnvd
- github.com/python/cpython/issues/150599nvd
- github.com/python/cpython/pull/150600nvd
- mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/nvd
News mentions
0No linked articles in our index yet.