Intel

AIKIDO-2026-235619

bzip2 is vulnerable to Out-of-bounds Write

Out-of-bounds WriteCVE-2026-42250 Published 2 days ago

48

Medium Risk

This Affects:

c++bzip2
0.0.1 - 1.0.8
Are you affected? Scan for Free

TL;DR

Affected versions of bzip2 have an off-by-one error in the bzip2recover utility's block-boundary scanner. A crafted file with more than 50,000 copies of the 48-bit bzip2 block-header magic writes one element past the global bStart/bEnd buffers, corrupting memory and crashing the process.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run the bzip2recover utility on untrusted or damaged .bz2 files.

Background info

bzip2 is vulnerable to Out-of-bounds Write in versions 0.0.1 - 1.0.8.

How to fix this

There is no patched release yet. Upgrade bzip2 once a version newer than 1.0.8 is published, or apply this patch. Until then, do not run bzip2recover on untrusted files.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform