Article
Cyber News / Article / Vulnerability in bzip2 software

CE
CERT Polska-2026-05-28
Vulnerability in bzip2 software
CERT Polska has received a report about vulnerability in bzip2 software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-42250: bzip2 contains an offâbyâone error in the bzip2recover utility. When processing a specially crafted file, the application performs an outâofâbounds write to a global buffer, resulting in memory corruption and a crash (denial of service).
This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
We thank MichaÅ Majchrowicz and Marcin Wyczechowski from AFINE Team for the responsible vulnerability report.
Related articles
in
[email protected] (The Hacker News)Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
Ab
AbinayaMapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks
2 days ago
An
Anne Aarness - Chris PrallCrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
9 days ago
