text explains which aspects/vulnerabilities correspond to which CVE.]
The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:
* The directory loop itself assumes a good record length. This is
CVE-2026-42494.
* The calculation of the System Use area may underflow. This is
CVE-2026-42495.
* The Rock Ridge extension loop assumes a good (inner) record length.
This is CVE-2026-62423.
* The Rock Ridge NM record processing assumes a good entry length.
This is CVE-2026-62424.
* The Rock Ridge CE record processing assumes a good size and offset.
This is CVE-2026-62425.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
XSA-443 added a mechanism to run pygrub de-privileged. Using this mode will mitigate the vulnerability. Ensuring that guests do not use the pygrub bootloader will avoid this vulnerability. For cases where the PV guest is known to be 64bit, and uses grub2 as a bootloader, pvgrub is a suitable alternative to pygrub. Running only HVM or PVH guests will avoid the vulnerability.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://xenbits.xenproject.org/xsa/advisory-497.html |
|
Tue, 28 Jul 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xen
Xen xen |
|
| Vendors & Products |
Xen
Xen xen |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: * The directory loop itself assumes a good record length. This is CVE-2026-42494. * The calculation of the System Use area may underflow. This is CVE-2026-42495. * The Rock Ridge extension loop assumes a good (inner) record length. This is CVE-2026-62423. * The Rock Ridge NM record processing assumes a good entry length. This is CVE-2026-62424. * The Rock Ridge CE record processing assumes a good size and offset. This is CVE-2026-62425. | |
| Title | buffer overruns in libfsimage iso9660 handling | |
| Weaknesses | CWE-130 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2026-07-28T14:51:03.684Z
Reserved: 2026-07-14T10:28:12.654Z
Link: CVE-2026-62423
Updated: 2026-07-28T14:49:14.359Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T19:00:04Z