| CVE ID | CVE-2026-42250 |
| Publication date | 28 May 2026 |
| Vendor | bzip2 |
| Product | bzip2 |
| Vulnerable versions | All before 1.0.9 |
| Vulnerability type (CWE) | Out-of-bounds Write (CWE-787) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in bzip2 software and participated in coordination of its disclosure.
The vulnerability CVE-2026-42250: bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).
This issue was fixed in bzip2 version 1.0.9
Credits
We thank Michał Majchrowicz and Marcin Wyczechowski from AFINE Team for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.