Additionally, the following CVE have been fixed:
CVE-2026-6100
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor` and
`bz2.BZ2Decompressor` when a memory allocation fails with a
`MemoryError` and the decompression instance is re-used. This
scenario can be triggered if the process is under memory pressure.
The vulnerability is only present if the program re-uses
decompressor instances across multiple decompression calls even
after a `MemoryError` is raised during decompression. Using the
helper functions to one-shot decompress data such as
`lzma.decompress()` and `bz2.decompress()` are not affected as a new
decompressor instance is used per call. If the decompressor instance
is not re-used after an error condition, this usage is similarly not
vulnerable.
For Debian 11 bullseye, these problems have been fixed in version
3.9.2-1+deb11u6.
We recommend that you upgrade your python3.9 packages.
Get the latest Linux and open source security news straight to your inbox.