Vulnerability in iso9660 Driver of libfsimage Affects Rock Ridge Extension Processing
CVE-2026-62423

5.5MEDIUM

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-62423?

The libfsimage iso9660 driver contains an implementation flaw in its handling of Rock Ridge extension processing. The vulnerability arises when lengths derived from attacker-controlled on-disk fields are not validated properly, which can lead to various unintended behaviors. This includes issues with the assumptions made regarding record lengths within the directory loop and the processing of System Use areas, potentially leading to further exploitation risks.

Affected Version(s)

Xen consult Xen advisory XSA-497

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Syed Abdul Khaliq of BugQore.
.