Directory Management Vulnerability in libfsimage's ISO9660 Driver by Vendor XenProject
CVE-2026-42495

Currently unrated

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-42495?

The libfsimage's ISO9660 driver contains vulnerabilities stemming from the mismanagement of lengths derived from attacker-controlled on-disk fields. Notably, the System Use area calculation may underflow, leading to unexpected behaviors. This oversight can potentially be exploited to introduce security risks, allowing for unauthorized data access or system instability.

Affected Version(s)

Xen consult Xen advisory XSA-497

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Syed Abdul Khaliq of BugQore.
.