Directory Management Vulnerability in libfsimage's ISO9660 Driver by Vendor XenProject
CVE-2026-42495
5.5MEDIUM
What is CVE-2026-42495?
The libfsimage's ISO9660 driver contains vulnerabilities stemming from the mismanagement of lengths derived from attacker-controlled on-disk fields. Notably, the System Use area calculation may underflow, leading to unexpected behaviors. This oversight can potentially be exploited to introduce security risks, allowing for unauthorized data access or system instability.
Affected Version(s)
Xen consult Xen advisory XSA-497
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Syed Abdul Khaliq of BugQore.