๐Ÿ” CVE Alert

CVE-2026-42495

UNKNOWN 0.0

buffer overruns in libfsimage iso9660 handling

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: * The directory loop itself assumes a good record length. This is CVE-2026-42494. * The calculation of the System Use area may underflow. This is CVE-2026-42495. * The Rock Ridge extension loop assumes a good (inner) record length. This is CVE-2026-62423. * The Rock Ridge NM record processing assumes a good entry length. This is CVE-2026-62424. * The Rock Ridge CE record processing assumes a good size and offset. This is CVE-2026-62425.

Vendor xen
Product xen
Published Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for xen xen

Be the first to know when new unknown vulnerabilities affecting xen xen are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Xen / Xen
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
xenbits.xenproject.org: https://xenbits.xenproject.org/xsa/advisory-497.html

Credits

This issue was discovered by Syed Abdul Khaliq of BugQore.