Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 11 python3.9 Critical UAF CVE-2026-6100 DLA-4532-1

debian lts
Calendar Grey April 15, 2026
Dist Debian Esm H88
Patched CVE issues in python3.9 include regression fixes for CVE-2025-15366, CVE-2025-15367, CVE-2026-6100 in Debian.
It was found that the patches for CVE-2025-15366 and CVE-2025-15367 break backward compatibility, and upstream decided not to backport those patches to older Python releases

Summary

Additionally, the following CVE have been fixed:

CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor` and
`bz2.BZ2Decompressor` when a memory allocation fails with a
`MemoryError` and the decompression instance is re-used. This
scenario can be triggered if the process is under memory pressure.
The vulnerability is only present if the program re-uses
decompressor instances across multiple decompression calls even
after a `MemoryError` is raised during decompression. Using the
helper functions to one-shot decompress data such as
`lzma.decompress()` and `bz2.decompress()` are not affected as a new
decompressor instance is used per call. If the decompressor instance
is not re-used after an error condition, this usage is similarly not
vulnerable.

For Debian 11 bullseye, these problems have been fixed in version
3.9.2-1+deb11u6.

We recommend that you upgrade your python3.9 packages.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: python3.9
Version: 3.9.2-1+deb11u6
CVE ID: CVE-2025-15366 CVE-2025-15367 CVE-2026-6100
Debian Bug:

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here