Vulnerability in iso9660 Driver of libfsimage Affects Rock Ridge Extension Processing
CVE-2026-62423
5.5MEDIUM
What is CVE-2026-62423?
The libfsimage iso9660 driver contains an implementation flaw in its handling of Rock Ridge extension processing. The vulnerability arises when lengths derived from attacker-controlled on-disk fields are not validated properly, which can lead to various unintended behaviors. This includes issues with the assumptions made regarding record lengths within the directory loop and the processing of System Use areas, potentially leading to further exploitation risks.
Affected Version(s)
Xen consult Xen advisory XSA-497
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Syed Abdul Khaliq of BugQore.