CVE-2026-42250: BZIP2

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67

Affected products

  • BZIP2 BZIP2: up to and including 1.0.8

Published 2026-05-28. Last modified 2026-06-17.