Junglewise Threat Intelligence

CVE-2026-42250: bzip2 off-by-one error in bzip2recover utility

CVE-2026-42250 · Severity: info · CVSS 5.1 · Published 2026-05-28

Executive brief

bzip2 is a widely used data compression tool and library. A vulnerability in its recovery utility could allow a specially crafted file to crash the application. This could lead to a denial of service when attempting to process or recover damaged compressed archives.

Technical details

An off-by-one error exists in the bzip2recover utility of bzip2. When the utility processes a specially crafted malicious file, it performs an out-of-bounds write to a global buffer. This memory corruption results in an application crash, causing a denial of service. The attack vector is local, requiring the utility to process a malicious file. The issue is classified as CWE-787 (Out-of-bounds Write) and is resolved in version 1.0.9.

Affected products

  • bzip2 bzip2 All versions before 1.0.9

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References