---
title: "CVE-2026-9669\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-9669?format=md
keywords: index, follow
---

# CVE-2026-9669

Publication date 8 June 2026

Last updated 6 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

bz2.BZ2Decompressor objects could be reused after a decompression error. If
an application caught the resulting OSError and retried with the same
decompressor, crafted input could cause the decompressor to resume from an
invalid internal state and perform out-of-bounds writes to a stack buffer.
This could crash the process when processing untrusted data.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| python3.10 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Fixed 3.10.12-1~22.04.16 |
| python3.12 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Fixed 3.12.3-1ubuntu0.15 |
| 22.04 LTS jammy | Not in release |
| python3.13 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| python3.14 | 26.04 LTS resolute | Fixed 3.14.4-1ubuntu0.1 |
| 25.10 questing | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| python2.7 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |
| python3.11 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Needs evaluation |
| python3.4 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 14.04 LTS trusty | Needs evaluation |
| python3.5 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |
| python3.6 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 18.04 LTS bionic | Needs evaluation |
| python3.7 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 18.04 LTS bionic | Needs evaluation |
| python3.8 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| python3.9 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2026-9669?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| python3.13 | * Upstream:   [619a12b](https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f) |
| python3.14 | * Upstream:   [157a5df](https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6) |

## Severity score breakdown

CVSS version:
CVSS v4.0

**Base score**

8.2 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Attack requirements | Present |
  | Privileges required | None |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | High |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.2 · High |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9669)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-9669)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-9669)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-9669)

### Related Ubuntu Security Notices (USN)

+ [USN-8509-1](https://usn.ubuntu.com/USN-8509-1)
+ Python vulnerabilities
+ 6 July 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-9669>
* <https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/>
* <http://www.openwall.com/lists/oss-security/2026/06/08/17>
