PT-2026-44373 · Bzip2+2 · Bzip2+2

·

CVE-2026-42250

·

Published

2026-05-28

·

Updated

2026-09-04

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions bzip2 versions prior to 1.0.9
Description The bzip2recover utility contains an off-by-one error. When processing a specially crafted file, the application performs an out-of-bounds write to a global buffer, which leads to memory corruption and a crash, resulting in a denial of service.
Recommendations Update to version 1.0.9.

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-88809
AZL-89190
CVE-2026-42250
ECHO-DFC7-0C27-52D8
OESA-2026-2786
OPENSUSE-SU-2026:11627-1
OPENSUSE-SU-2026:21762-1
RHSA-2026:30268
SUSE-SU-2026:3925-1
USN-8685-1

Affected Products

Linuxmint
Ubuntu
Bzip2