PT-2026-44373 · Bzip2 · Bzip2

Marcin Wyczechowski

+1

·

Published

2026-05-28

·

Updated

2026-06-02

·

CVE-2026-42250

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions bzip2 versions prior to 1.0.9
Description The bzip2recover utility contains an off-by-one error. When processing a specially crafted file, the application performs an out-of-bounds write to a global buffer, which leads to memory corruption and a crash, resulting in a denial of service.
Recommendations Update to version 1.0.9.

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42250
ECHO-DFC7-0C27-52D8

Affected Products

Bzip2