[LFS Trac] #5910: python CVE-2026-6100

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5910: python CVE-2026-6100
-------------------------+----------------------
 Reporter:  Joe Locash   |      Owner:  lfs-book
     Type:  enhancement  |     Status:  new
 Priority:  highest      |  Milestone:  13.1
Component:  Book         |    Version:  git
 Severity:  normal       |   Keywords:
-------------------------+----------------------
 {{{
 There is a CRITICAL severity vulnerability affecting CPython.

 Use-after-free (UAF) was possible in the lzma.LZMADecompressor,
 bz2.BZ2Decompressor, and gzip.GzipFile when a memory allocation fails
 with a MemoryError and the decompression instance is re-used. This
 scenario can be triggered if the process is under memory pressure. The fix
 cleans up the dangling pointer in this specific error condition.

 The vulnerability is only present if the program re-uses decompressor
 instances across multiple decompression calls even after a MemoryError is
 raised during decompression. Using the helper functions to one-shot
 decompress data such as lzma.decompress(), bz2.decompress(),
 gzip.decompress(), and zlib.decompress() are not affected as a new
 decompressor instance is created for each call. If the decompressor
 instance is not re-used after an error condition, this usage is similarly
 not vulnerable.

 Please see the linked CVE ID for the latest information on affected
 versions:

     https://www.cve.org/CVERecord?id=CVE-2026-6100
     https://github.com/python/cpython/pull/148396
 }}}

 Source: https://mail.python.org/archives/list/security-
 [email protected]/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5910>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.