Off-by-one flaw patched in bzip2recover
A coordinated disclosure reveals an off-by-one bug in bzip2's bzip2recover utility that can crash the app via a crafted file.
CERT Polska coordinated the disclosure of CVE-2026-42250, a vulnerability affecting the bzip2recover utility within the widely-used bzip2 compression software. The flaw is an off-by-one error that leads to an out-of-bounds write to a global buffer when processing a specially crafted archive file, resulting in memory corruption and application crash (denial of service).
The issue was reported responsibly by researchers Michał Majchrowicz and Marcin Wyczechowski of the AFINE Team, and has since been patched upstream via commit 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67. No evidence of active exploitation is mentioned; this is a standard coordinated vulnerability disclosure with a fix already available. Organizations using bzip2recover to process untrusted or externally-supplied archive files should apply the patch to prevent denial-of-service conditions.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-42250
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free