CVE-2026-42250: Off-by-One Leading to Out-of-Bounds Write in bzip2
bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).
This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
Other sources
Off-by-One Leading to Out-of-Bounds Write in bzip2
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.15.0.aks0-15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.0.8-2 - Upgrade
Upgrade
bzip2to a version that resolves this vulnerability.Patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42250?
CVE-2026-42250 has a medium severity rating of 5.1 according to the CVSS score.
How do I fix CVE-2026-42250?
To fix CVE-2026-42250, you should upgrade bzip2 to version 1.0.9 or later.
What type of vulnerability is CVE-2026-42250?
CVE-2026-42250 is an off-by-one error leading to an out-of-bounds write.
What are the consequences of CVE-2026-42250?
The consequences of CVE-2026-42250 include memory corruption and potential denial of service.
Which software is affected by CVE-2026-42250?
CVE-2026-42250 affects the bzip2 compression utility, specifically the bzip2recover utility.