What is CVE-2026-42495?
This CVE covers a vulnerability in Xen's libfsimage iso9660 driver where the directory and Rock Ridge/SUSP walk derives lengths from attacker-controlled on-disk fields without validation. This could potentially impact unauthenticated attackers. Applying relevant updates is recommended to mitigate the risk.
Azərbaycanca: Bu CVE Xen-in libfsimage kitabxanasının iso9660 sürücüsündəki zəifliyi əhatə edir: hücumçu tərəfindən idarə olunan disk sahələrindən uzunluq dəyərləri yoxlanılmadan götürülür. Bu, potensial olaraq autentifikasiya olunmamış təcavüzkara təsir göstərə bilər. Riski azaltmaq üçün müvafiq yeniləmələri tətbiq etmək tövsiyə olunur.
FAQ2
In which component was the CVE-2026-42495 vulnerability discovered?
The vulnerability was discovered in the iso9660 driver of Xen's libfsimage library.
Does exploiting this vulnerability require the attacker to be authenticated?
No, this vulnerability could potentially impact unauthenticated attackers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.