Directory and Rock Ridge Vulnerabilities in libfsimage's iso9660 Driver
CVE-2026-42494

Currently unrated

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-42494?

The libfsimage iso9660 driver is vulnerable due to insufficient validation of lengths derived from attacker-controlled on-disk fields. Specifically, the directory loop does not validate the record length, allowing potential exploits leading to data corruption or unauthorized access. Additional concerns arise from Rock Ridge processing, where assumptions about record lengths and sizes create multiple vectors for exploitation. Addressing these vulnerabilities is crucial for maintaining system integrity and safeguarding against attacks.

Affected Version(s)

Xen consult Xen advisory XSA-497

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Syed Abdul Khaliq of BugQore.
.