Article

    Cyber News / Article / Vulnerability in bzip2 software

    Vulnerability in bzip2 software
    CE
    CERT Polska-2026-05-28

    Vulnerability in bzip2 software

    CERT Polska has received a report about vulnerability in bzip2 software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-42250: bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).

    This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67

    We thank Michał Majchrowicz and Marcin Wyczechowski from AFINE Team for the responsible vulnerability report.

    Original source