CVE-2026-42250

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
CVSS

No CVSS.

Configurations

No configuration.

History

28 May 2026, 18:16

Type Values Removed Values Added
Summary (en) bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 version 1.0.9 (en) bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
References
  • () https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/ -
  • () https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67 -

28 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 14:16

Updated : 2026-06-05 08:16


NVD link : CVE-2026-42250

Mitre link : CVE-2026-42250

CVE.ORG link : CVE-2026-42250


JSON object : View

Products Affected

No product.

CWE
CWE-787

Out-of-bounds Write