Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56

Количество 56

ubuntu логотип

CVE-2026-6100

5 месяцев назад

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-6100

5 месяцев назад

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-6100

5 месяцев назад

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2026-6100

3 месяца назад

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-6100

5 месяцев назад

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2 ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-pg25-7cx5-cvcm

5 месяцев назад

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2026-05838

5 месяцев назад

Уязвимость функций lzma.LZMADecompressor(), bz2.BZ2Decompressor() и gzip.GzipFile() интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-80-0056

3 месяца назад

Уязвимость python3.13

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-80-0055

3 месяца назад

Уязвимость python3.14

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-80-0054

3 месяца назад

Уязвимость python3.12

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-80-0053

3 месяца назад

Уязвимость python3.11

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-80-0052

3 месяца назад

Уязвимость python3.10

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-80-0051

3 месяца назад

Уязвимость python3.9

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-80-0050

3 месяца назад

Уязвимость python3.8

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-73-0046

3 месяца назад

Уязвимость python3.13

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-73-0045

3 месяца назад

Уязвимость python3.12

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-73-0044

3 месяца назад

Уязвимость python3.11

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-73-0043

3 месяца назад

Уязвимость python3.10

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-73-0042

3 месяца назад

Уязвимость python3.9

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260623-73-0041

3 месяца назад

Уязвимость python3

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
msrc логотип
CVE-2026-6100

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

CVSS3: 8.1
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2 ...

CVSS3: 8.1
1%
Низкий
5 месяцев назад
github логотип
GHSA-pg25-7cx5-cvcm

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-05838

Уязвимость функций lzma.LZMADecompressor(), bz2.BZ2Decompressor() и gzip.GzipFile() интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.7
1%
Низкий
5 месяцев назад
redos логотип
ROS-20260623-80-0056

Уязвимость python3.13

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-80-0055

Уязвимость python3.14

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-80-0054

Уязвимость python3.12

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-80-0053

Уязвимость python3.11

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-80-0052

Уязвимость python3.10

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-80-0051

Уязвимость python3.9

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-80-0050

Уязвимость python3.8

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-73-0046

Уязвимость python3.13

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-73-0045

Уязвимость python3.12

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-73-0044

Уязвимость python3.11

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-73-0043

Уязвимость python3.10

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-73-0042

Уязвимость python3.9

CVSS3: 8.7
1%
Низкий
3 месяца назад
redos логотип
ROS-20260623-73-0041

Уязвимость python3

CVSS3: 8.7
1%
Низкий
3 месяца назад

Уязвимостей на страницу