https://seclists.org/oss-sec/2026/q2/846: [oss-security][CVE-2026-9669] CPython: bz2.BZ2Decompssor use after error can cause a stack buffer overflow
Published Jun 8, 2026
·Updated
Affected Software
1 affected component
Python CPython<3.16.0
Frequently Asked Questions
1
What is the severity of CVE-2026-9669?
The severity of CVE-2026-9669 is considered high due to the potential for a stack buffer overflow.
2
How do I fix CVE-2026-9669?
To fix CVE-2026-9669, upgrade to CPython version 3.16.0 or later, where the vulnerability has been addressed.
3
Which versions of CPython are affected by CVE-2026-9669?
CVE-2026-9669 affects all CPython versions prior to 3.16.0.
4
What types of attacks can CVE-2026-9669 lead to?
CVE-2026-9669 can lead to potential execution of arbitrary code due to the stack buffer overflow.
5
Who reported CVE-2026-9669?
CVE-2026-9669 was reported by Emma Smith as part of the security announcement.