Description
bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
Problem types
Product status
Any version
35d122a3df8b0cc4082a4d89fdc6ee99f375fe67 (custom)
Credits
Michał Majchrowicz (AFINE Team)
Marcin Wyczechowski (AFINE Team)
References
cert.pl/en/posts/2026/05/CVE-2026-42250/
sourceware.org/bzip2/
inbox.sourceware.org/...60528145407.293768-1-mark@klomp.org/
sourceware.org/...d=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67