| CVE ID | CVE-2026-42250 |
| Publication date | 28 May 2026 |
| Vendor | bzip2 |
| Product | bzip2 |
| Vulnerable versions | All through 1.0.8 |
| Vulnerability type (CWE) | Out-of-bounds Write (CWE-787) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in bzip2 software and participated in coordination of its disclosure.
The vulnerability CVE-2026-42250: bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).
This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
Credits
We thank Michał Majchrowicz and Marcin Wyczechowski from AFINE Team for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.