Security Advisory

CVE-2026-42250

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-28 13:15:19
Last updated 2026-06-05 07:47:33
Assigner CERT-PL
CVSS score 5.1
State PUBLISHED

Description

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67