PT-2026-32487 · Python+5 · Cpython+5

·

CVE-2026-6100

·

Published

2026-04-13

·

Updated

2026-08-28

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Python (affected versions not specified)
Description A use-after-free flaw exists in the decompression modules of Python, specifically within lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile. This issue occurs when a program re-uses a decompression object after a MemoryError is raised due to memory allocation failure, typically during periods of high memory pressure. A use-after-free is a condition where a program continues to use a pointer after it has been freed, which can lead to memory corruption. Exploitation of this flaw could allow an attacker to execute arbitrary code or access sensitive data. The issue is not present when using one-shot decompression helper functions such as lzma.decompress(), bz2.decompress(), gzip.decompress(), and zlib.decompress(), as these create a new instance for every call.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, avoid re-using decompressor instances across multiple calls if a MemoryError has occurred.

Exploit

DoS

RCE

Use After Free

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:10711
ALSA-2026:10745
ALSA-2026:10774
ALSA-2026:10949
ALSA-2026:10950
ALSA-2026:11062
ALSA-2026:11077
ALSA-2026:19019
ALSA-2026:19064
ALSA-2026:19175
ALSA-2026:19176
ALSA-2026:19177
ALSA-2026:19216
AZL-83051
BDU:2026-05838
BIT-LIBPYTHON-2026-6100
BIT-PYTHON-2026-6100
BIT-PYTHON-MIN-2026-6100
CVE-2026-6100
ECHO-5806-1424-7B47
OESA-2026-2115
OESA-2026-2116
OESA-2026-2117
OPENSUSE-SU-2026:10647-1
OPENSUSE-SU-2026:10648-1
OPENSUSE-SU-2026:10667-1
OPENSUSE-SU-2026:11068-1
OPENSUSE-SU-2026:11100-1
OPENSUSE-SU-2026:11181-1
OPENSUSE-SU-2026:21459-1
PSF-2026-18
RHSA-2026:10117
RHSA-2026:10711
RHSA-2026:10745
RHSA-2026:10774
RHSA-2026:10949
RHSA-2026:10950
RHSA-2026:11062
RHSA-2026:11077
RHSA-2026:13692
RHSA-2026:14652
RHSA-2026:14653
RHSA-2026:14656
RHSA-2026:19019
RHSA-2026:19064
RHSA-2026:19175
RHSA-2026:19176
RHSA-2026:19177
RHSA-2026:19216
RHSA-2026:19549
RHSA-2026:19570
RHSA-2026:19571
RHSA-2026:19576
RHSA-2026:19590
RHSA-2026:52400
RHSA-2026:8822
RHSA-2026:8824
RHSA-2026:9228
SUSE-SU-2026:1715-1
SUSE-SU-2026:1818-1
SUSE-SU-2026:1937-1
SUSE-SU-2026:1947-1
SUSE-SU-2026:2055-1
SUSE-SU-2026:22959-1
SUSE-SU-2026:23191-1
SUSE-SU-2026:23212-1
SUSE-SU-2026:2387-1
SUSE-SU-2026:2464-1
SUSE-SU-2026:2664-1
SUSE-SU-2026:3104-1
SUSE-SU-2026:3132-1
SUSE-SU-2026:3855-1
USN-8509-1

Affected Products

Cpython
Ibm Aix
Linuxmint
Red Os
Rocky Linux
Ubuntu