bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.2epss 0.4%
probabilidad de explotación
0.4%top 65% de las CVE
explotación observada
noninguna fuente lo reporta
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
Python Software Foundation · CPythonReferencias
https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036ehttps://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6fhttps://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702dhttps://github.com/python/cpython/issues/150599https://github.com/python/cpython/pull/150600https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/http://www.openwall.com/lists/oss-security/2026/06/08/17