← Vulnerability feed

Vulnerability record · CVE-2026-6100 · published 13 April 2026

CVE-2026-6100: Use after free vulnerability

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

9.1 CVSS 4.0 Critical EPSS 0.76% · top 46.5% CWE-416 · Use after freeCWE-787 · Out-of-bounds write Awaiting Analysis
9.1CVSS 4.0 base score
0.76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
55References
13 Aug 2026Last modified by NVD

Description

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

References

LinkTags
https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e
https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d
https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2
https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20
https://github.com/python/cpython/commit/e20c6c9667c99ecaab96e1a2b3767082841ffc8b
https://github.com/python/cpython/commit/ea8d735eb084cf8cc021df1a30e90d10a8f052e3
https://github.com/python/cpython/issues/148395
https://github.com/python/cpython/pull/148396
https://mail.python.org/archives/list/[email protected]/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/
http://www.openwall.com/lists/oss-security/2026/04/13/10
https://access.redhat.com/errata/RHSA-2026:10117
https://access.redhat.com/errata/RHSA-2026:10140
https://access.redhat.com/errata/RHSA-2026:10141
https://access.redhat.com/errata/RHSA-2026:10711
https://access.redhat.com/errata/RHSA-2026:10745
https://access.redhat.com/errata/RHSA-2026:10774
https://access.redhat.com/errata/RHSA-2026:10949
https://access.redhat.com/errata/RHSA-2026:10950
https://access.redhat.com/errata/RHSA-2026:11062
https://access.redhat.com/errata/RHSA-2026:11077
https://access.redhat.com/errata/RHSA-2026:11768
https://access.redhat.com/errata/RHSA-2026:13692
https://access.redhat.com/errata/RHSA-2026:13812
https://access.redhat.com/errata/RHSA-2026:14652
https://access.redhat.com/errata/RHSA-2026:14653
https://access.redhat.com/errata/RHSA-2026:14656
https://access.redhat.com/errata/RHSA-2026:16699
https://access.redhat.com/errata/RHSA-2026:17525
https://access.redhat.com/errata/RHSA-2026:17619
https://access.redhat.com/errata/RHSA-2026:19019
https://access.redhat.com/errata/RHSA-2026:19064
https://access.redhat.com/errata/RHSA-2026:19175
https://access.redhat.com/errata/RHSA-2026:19176
https://access.redhat.com/errata/RHSA-2026:19177
https://access.redhat.com/errata/RHSA-2026:19216
https://access.redhat.com/errata/RHSA-2026:19549
https://access.redhat.com/errata/RHSA-2026:19570
https://access.redhat.com/errata/RHSA-2026:19571
https://access.redhat.com/errata/RHSA-2026:19576
https://access.redhat.com/errata/RHSA-2026:19590

Track CVE-2026-6100 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.0CVE-2026-68820Windows Ancillary Function Driver for WinSock use-after-free privilege escalationThe Windows Ancillary Function Driver for WinSock (afd.sys) contains a use-after-free (CWE-416) that lets an authorized local attacker elevate privil…KEVEPSS 0.33%analysed8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed8.8CVE-2010-0249Microsoft Internet Explorer use-after-free enables remote code executionInternet Explorer 6, 7 and 8 mishandle objects in memory, leaving a dangling pointer that can be reused after the object is freed. A remote attacker …KEVEPSS 92%analysed7.8CVE-2020-9715Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat and Reader contain a use-after-free (CWE-416) flaw affecting versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and ea…KEVEPSS 49%analysed8.8CVE-2026-5281Google Chrome Dawn use-after-free allows remote code executionChrome versions before 146.0.7680.178 contain a use-after-free flaw in the Dawn graphics component. An attacker who has already compromised the rende…KEVEPSS 0.70%analysed8.8CVE-2023-43000Apple WebKit use-after-free via malicious web contentA use-after-free flaw in Apple's WebKit engine was fixed by improved memory management in macOS Ventura 13.5, iOS/iPadOS 16.6, Safari 16.6, and iOS/i…KEVEPSS 3.9%analysed7.8CVE-2023-41974Apple iOS and iPadOS use-after-free allows kernel code executionA use-after-free flaw in Apple iOS and iPadOS was fixed through improved memory management in iOS 17, iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. Becaus…KEVEPSS 1.9%analysed8.8CVE-2026-2441Google Chrome CSS use-after-free enables sandbox code executionChrome before 145.0.7632.75 contains a use-after-free in CSS handling. A crafted HTML page can trigger the flaw and let a remote attacker run arbitra…KEVEPSS 55%analysed

Source: NIST National Vulnerability Database (record CVE-2026-6100), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.