Skip to content

CVE-2026-9669 on CTRL-OS 26.05

Aliases: CVE-2026-9669

Packages: python313

Status: Plausible, Resolved

Advisory Information

bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.

Updates

2026-07-21 16:35 CEST

Metadata changes:

  • Status for package python313: “Resolved” (fff38d56fb8e15a140da141149c596766b838d0b)

(Amended on: 2026-07-21 16:36 CEST)

2026-07-21 16:35 CEST

Metadata changes:

  • Status for package python314: “Resolved” (b907b8ba5e335b35aed7b8b2d2f2058d8f10e055)

(Amended on: 2026-07-21 16:36 CEST)

2026-07-21 16:35 CEST

Metadata changes:

  • Status for package python315: “Resolved” (ee8e35d073a3e2b52c4bb8feb2d584b36c32568f)

2026-07-21 16:25 CEST

Metadata changes:

  • Status for package python311: “Plausible
  • Status for package python312: “Plausible
  • Status for package python313: “Plausible
  • Status for package python314: “Plausible
  • Status for package python315: “Plausible

(Amended on: 2026-07-21 16:35 CEST)

2026-06-11 16:57 CEST

Metadata changes:

  • Status for package python311: “New
  • Status for package python312: “New
  • Status for package python313: “New
  • Status for package python314: “New
  • Status for package python315: “New

(Amended on: 2026-07-20 23:04 CEST)