Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42250

Опубликовано: 28 мая 2026
Источник: debian
EPSS Низкий

Описание

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67

Пакеты

ПакетСтатусВерсия исправленияРелизТип
bzip2unfixedpackage
bzip2no-dsatrixiepackage
bzip2no-dsabookwormpackage
bzip2no-dsabullseyepackage

Примечания

  • https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/

  • Fixed by: https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67

EPSS

Процентиль: 3%
0.00126
Низкий

Связанные уязвимости

ubuntu
2 месяца назад

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67

CVSS3: 5
redhat
2 месяца назад

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67

nvd
2 месяца назад

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67

msrc
2 месяца назад

Off-by-One Leading to Out-of-Bounds Write in bzip2

github
2 месяца назад

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 version 1.0.9

EPSS

Процентиль: 3%
0.00126
Низкий