bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.2epss 0.4%
probabilidade de exploração
0.4%top 66% das CVEs
exploração observada
nãonenhuma fonte reporta
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Python Software Foundation · CPythonReferências
https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036ehttps://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6fhttps://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702dhttps://github.com/python/cpython/issues/150599https://github.com/python/cpython/pull/150600https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/http://www.openwall.com/lists/oss-security/2026/06/08/17