Vulnerability in iso9660 Driver of libfsimage Affects Rock Ridge Extension Processing
CVE-2026-62423

Currently unrated

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-62423?

The libfsimage iso9660 driver contains an implementation flaw in its handling of Rock Ridge extension processing. The vulnerability arises when lengths derived from attacker-controlled on-disk fields are not validated properly, which can lead to various unintended behaviors. This includes issues with the assumptions made regarding record lengths within the directory loop and the processing of System Use areas, potentially leading to further exploitation risks.

Affected Version(s)

Xen consult Xen advisory XSA-497

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Syed Abdul Khaliq of BugQore.
.