CVE-2016-3189: Bzip BZIP2

Medium severity, CVSS 6.5. EPSS: 15.6% chance of exploitation in the next 30 days.

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

Affected products

  • Bzip BZIP2: version 1.0.6 only
  • Python Python: from 3.7.0, before 3.7.13 (fixed in 3.7.13); from 3.8.0, before 3.8.13 (fixed in 3.8.13); from 3.9.0, before 3.9.11 (fixed in 3.9.11); from 3.10.0, before 3.10.3 (fixed in 3.10.3)

Published 2016-06-30. Last modified 2026-06-17.