[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
* The directory loop itself assumes a good record length. This is CVE-2026-42494.
* The calculation of the System Use area may underflow. This is CVE-2026-42495.
* The Rock Ridge extension loop assumes a good (inner) record length. This is CVE-2026-62423.
* The Rock Ridge NM record processing assumes a good entry length. This is CVE-2026-62424.
* The Rock Ridge CE record processing assumes a good size and offset. This is CVE-2026-62425.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Aug 12, 2026 | Jul 28, 2026 |
| Debian | — | Upgrade xen | Aug 11, 2026 | Aug 11, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub