CVE-2026-62424
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
28/07/2026
Última modificación:
28/07/2026
Descripción
*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the<br />
text explains which aspects/vulnerabilities correspond to which CVE.]<br />
<br />
The directory and Rock Ridge / SUSP walk in libfsimage&#39;s iso9660 driver<br />
derives several lengths directly from attacker-controlled on-disk fields<br />
without validating them:<br />
<br />
* The directory loop itself assumes a good record length. This is<br />
CVE-2026-42494.<br />
<br />
* The calculation of the System Use area may underflow. This is<br />
CVE-2026-42495.<br />
<br />
* The Rock Ridge extension loop assumes a good (inner) record length.<br />
This is CVE-2026-62423.<br />
<br />
* The Rock Ridge NM record processing assumes a good entry length.<br />
This is CVE-2026-62424.<br />
<br />
* The Rock Ridge CE record processing assumes a good size and offset.<br />
This is CVE-2026-62425.



