Vulnerability Description
bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
Related Weaknesses (CWE)
References
- https://cert.pl/en/posts/2026/05/CVE-2026-42250/
- https://inbox.sourceware.org/bzip2-devel/[email protected]/
- https://sourceware.org/bzip2/
- https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f37
FAQ
What is CVE-2026-42250?
CVE-2026-42250 is a documented vulnerability. bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corrup...
How severe is CVE-2026-42250?
CVSS scoring is not yet available for CVE-2026-42250. Check NVD for updates.
Is there a patch for CVE-2026-42250?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.