From 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67 Mon Sep 17 00:00:00 2001 From: Mark Wielaard Date: Thu, 28 May 2026 16:15:45 +0200 Subject: bzip2recover: Make sure to not process more than BZ_MAX_HANDLED_BLOCKS There is an off-by-one in the check before calling tooManyBlocks. This causes the scanning loop to run one more time and cause a possible read or write one past the global bStart, bEnd, rbStart and rbEnd buffers. There are no known exploits of this issue and you will need to compile with something like gcc -fsanitize=address (ASAN AddressSanitizer) to observe the faulty read/write. This has been assigned CVE-2026-42250. --- bzip2recover.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/bzip2recover.c b/bzip2recover.c index a8131e0..4b1c219 100644 --- a/bzip2recover.c +++ b/bzip2recover.c @@ -402,7 +402,7 @@ Int32 main ( Int32 argc, Char** argv ) rbEnd[rbCtr] = bEnd[currBlock]; rbCtr++; } - if (currBlock >= BZ_MAX_HANDLED_BLOCKS) + if (currBlock >= BZ_MAX_HANDLED_BLOCKS - 1) tooManyBlocks(BZ_MAX_HANDLED_BLOCKS); currBlock++; -- cgit v1.2.3-55-g6feb