Directory Processing Vulnerability in libfsimage's ISO9660 Driver Affects Xen Project
CVE-2026-62425
5.5MEDIUM
What is CVE-2026-62425?
The libfsimage ISO9660 driver contains a vulnerability where it derives lengths from attacker-controlled on-disk fields without proper validation. This flaw can lead to erroneous assumptions about record lengths in various processing tasks, creating potential security risks. Specifically, the processing of the Rock Ridge NM and CE records does not verify the integrity of entry sizes and offsets, allowing an attacker to exploit these weaknesses. This could result in unexpected behaviors or system compromise.
Affected Version(s)
Xen consult Xen advisory XSA-497
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Syed Abdul Khaliq of BugQore.