Description
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 pypi | | | 3.15.0rc2 |
 debian 12 | | =3.11.2-6 || =3.11.2-6+deb12u1 || =3.11.2-6+deb12u2 || =3.11.2-6+deb12u3 || =3.11.2-6+deb12u4 || =3.11.2-6+deb12u5 || =3.11.2-6+deb12u6 || =3.11.2-6+deb12u7 || =3.11.2-6+deb12u8 || =3.11.3-1 || =3.11.3-2 || =3.11.4-1 || =3.11.5-1 || =3.11.5-2 || =3.11.5-3 || =3.11.6-1 || =3.11.6-2 || =3.11.6-3 || =3.11.6-3~hurd.2 || =3.11.7-1 || =3.11.7-2 || =3.11.8-1 || =3.11.8-1.1~exp1 || =3.11.8-1.1~exp2 || =3.11.8-2 || =3.11.8-3 || =3.11.8-3+hurd.1 || =3.11.9-1 | - |
 debian 13 | | =3.13.11-1 || =3.13.12-1 || =3.13.14-1 || =3.13.15-1 || =3.13.5-2 || =3.13.5-2+deb13u1 || =3.13.5-2+deb13u2 || =3.13.5-2+deb13u3 || =3.13.5-2+deb13u4 || =3.13.5-2+deb13u5 || =3.13.6-1 || =3.13.7-1 || =3.13.8-1 || =3.13.9-1 | - |
 debian 14 | | =3.13.11-1 || =3.13.12-1 || =3.13.14-1 || =3.13.15-1 || =3.13.5-2 || =3.13.6-1 || =3.13.7-1 || =3.13.8-1 || =3.13.9-1 | - |
 debian 14 | | =3.14.0-1 || =3.14.0-2 || =3.14.0-3 || =3.14.0-4 || =3.14.0-5 || =3.14.0~a7-1 || =3.14.0~b1-1 || =3.14.0~b2-1 || =3.14.0~b3-1 || =3.14.0~b4-1 || =3.14.0~rc1-1 || =3.14.0~rc2-1 || =3.14.0~rc3-1 || =3.14.2-1 || =3.14.3-1 || =3.14.3-2 || =3.14.3-3 || =3.14.3-4 || =3.14.3-5 || =3.14.4-1 || =3.14.4-2 || =3.14.5-1 || =3.14.5~rc1-1 || =3.14.6-1 || =3.14.7-1 || =3.14.7-2 || >=0 <3.14.7-3 | 3.14.7-3 |
 debian 14 | | =3.15.0~a8-1 || =3.15.0~a8-2 || =3.15.0~b1-1 || =3.15.0~b1-2 || =3.15.0~b1-3 || =3.15.0~b2-1 || =3.15.0~b3-1 || =3.15.0~b4-1 || =3.15.0~rc1-1 || >=0 <3.15.0~rc2-1 | 3.15.0~rc2-1 |