What is CVE-2026-42494?
CVE-2026-42494 is a vulnerability in the iso9660 driver of libfsimage where directory and Rock Ridge/SUSP walks use lengths derived from attacker-controlled on-disk fields without validation. This could lead to arbitrary code execution on affected systems using this driver, so applying software updates is strongly recommended.
Azərbaycanca: CVE-2026-42494 libfsimage-in iso9660 sürücüsündəki zəiflikdir. Təcavüzkar tərəfindən idarə olunan disk sahələrindən uzunluq dəyərləri yoxlanılmadan götürüldüyü üçün təsirə məruz qalan sistemlərdə ixtiyari kod icrası riski yaradır. Bu sürücüdən istifadə edən sistemlərdə proqram təminatı yeniləmələri tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
In which software component was CVE-2026-42494 discovered?
This vulnerability was discovered in the iso9660 driver of libfsimage.
What risk does successful exploitation of CVE-2026-42494 pose?
It poses a risk of arbitrary code execution because directory and Rock Ridge/SUSP walks use lengths derived from attacker-controlled on-disk fields without validation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.