VORANT. Threat Intelligence Sign in Get the full feed

bzip2recover off-by-one flaw triggers memory corruption

medium vulnerability

An off-by-one error in bzip2recover causes out-of-bounds writes when processing crafted files, leading to denial of service; patched in commit 35d122a3df8b.

CERT Polska coordinated disclosure of CVE-2026-42250, an off-by-one vulnerability in the bzip2recover utility. When processing a specially crafted file, the application performs an out-of-bounds write to a global buffer, resulting in memory corruption and application crash. The flaw represents a classic buffer overflow condition that leads to denial of service.

The vulnerability was responsibly reported by researchers Michał Majchrowicz and Marcin Wyczechowski from AFINE Team. The issue has been addressed in bzip2 patch commit 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67. Organizations using bzip2recover should apply the patch to mitigate the denial-of-service risk.

While bzip2 is a widely deployed compression utility, the vulnerability is limited to the recovery tool rather than the main compression/decompression functions. The impact is constrained to availability rather than confidentiality or integrity, and exploitation requires processing of a malicious file.

Mentioned in this report

Vulnerabilities CVE-2026-42250

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-42250

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free