(cherry picked from commit a7b6fa34c1)
(cherry picked from commit 2f092df439722bc95d790d0a2c734e637ff08006)
35 lines
1.1 KiB
Diff
35 lines
1.1 KiB
Diff
From 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67 Mon Sep 17 00:00:00 2001
|
|
From: Mark Wielaard <mark@klomp.org>
|
|
Date: Thu, 28 May 2026 16:15:45 +0200
|
|
Subject: bzip2recover: Make sure to not process more than
|
|
BZ_MAX_HANDLED_BLOCKS
|
|
|
|
There is an off-by-one in the check before calling tooManyBlocks. This
|
|
causes the scanning loop to run one more time and cause a possible
|
|
read or write one past the global bStart, bEnd, rbStart and rbEnd
|
|
buffers. There are no known exploits of this issue and you will need
|
|
to compile with something like gcc -fsanitize=address (ASAN
|
|
AddressSanitizer) to observe the faulty read/write.
|
|
|
|
This has been assigned CVE-2026-42250.
|
|
---
|
|
bzip2recover.c | 2 +-
|
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
|
|
diff --git bzip2recover.c bzip2recover.c
|
|
index a8131e0..4b1c219 100644
|
|
--- bzip2recover.c
|
|
+++ bzip2recover.c
|
|
@@ -402,7 +402,7 @@ Int32 main ( Int32 argc, Char** argv )
|
|
rbEnd[rbCtr] = bEnd[currBlock];
|
|
rbCtr++;
|
|
}
|
|
- if (currBlock >= BZ_MAX_HANDLED_BLOCKS)
|
|
+ if (currBlock >= BZ_MAX_HANDLED_BLOCKS - 1)
|
|
tooManyBlocks(BZ_MAX_HANDLED_BLOCKS);
|
|
currBlock++;
|
|
|
|
--
|
|
cgit
|
|
|