Logo
vulnerabilityCVE-2026-42250
Name
CVE-2026-42250
Source
NVD ( link)Debian ( link)
Description
bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
bzip2
Exploitable

Vulnerability Ratings#


4.8
CVSSv4
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
1.0.8
Exploitable
openwrt
master
1.0.8-r1
Exploitable
openwrt
openwrt-25.12
1.0.8-r1
Exploitable
yocto
kirkstone
1.0.8
Exploitable
yocto
master
1.0.8
Patched
yocto
scarthgap
1.0.8
Patched

Resolved with patches#


bzip2 (yocto:master)

#
Title
Author
Resolve
1
bzip2recover: Make sure to not process more than
Mark Wielaard <mark@klomp.org>
CVE-2026-42250

bzip2 (yocto:scarthgap)

#
Title
Author
Resolve
1
bzip2recover: Make sure to not process more than
Mark Wielaard <mark@klomp.org>
CVE-2026-42250