CyberRota Analysis
AI-GeneratedThe vulnerability affects the iso9660 driver in libfsimage, where several processes assume valid lengths derived from attacker-controlled on-disk fields, leading to potential exploitation. The impact includes possible denial of service or arbitrary code execution due to improper validation of directory and record lengths. Organizations using systems that rely on libfsimage for handling ISO images should prioritize addressing this vulnerability to mitigate risks associated with maliciously crafted images.
Original NVD Description
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: * The directory loop itself assumes a good record length. This is CVE-2026-42494. * The calculation of the System Use area may underflow. This is CVE-2026-42495. * The Rock Ridge extension loop assumes a good (inner) record length. This is CVE-2026-62423. * The Rock Ridge NM record processing assumes a good entry length. This is CVE-2026-62424. * The Rock Ridge CE record processing assumes a good size and offset. This is CVE-2026-62425.