SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-62423

MEDIUM · CVSS 5.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The vulnerability in the iso9660 driver of libfsimage allows for the processing of attacker-controlled on-disk fields without proper validation, specifically in the handling of Rock Ridge NM and CE records, which can lead to potential denial-of-service or arbitrary code execution. Organizations utilizing this library should prioritize addressing this issue to mitigate risks associated with untrusted input processing. It is particularly critical for developers and maintainers of software that rely on libfsimage for handling ISO images.

CVE
CVE-2026-62423
Severity
MEDIUM
CVSS
5.5
EPSS
0.20%

Original NVD Description

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: * The directory loop itself assumes a good record length. This is CVE-2026-42494. * The calculation of the System Use area may underflow. This is CVE-2026-42495. * The Rock Ridge extension loop assumes a good (inner) record length. This is CVE-2026-62423. * The Rock Ridge NM record processing assumes a good entry length. This is CVE-2026-62424. * The Rock Ridge CE record processing assumes a good size and offset. This is CVE-2026-62425.