What is CVE-2026-62423?
The vulnerability in libfsimage's iso9660 driver occurs during directory and Rock Ridge / SUSP walk, where several lengths are derived directly from attacker-controlled on-disk fields without proper validation. Successful exploitation could allow an attacker to manipulate read/write operations through a specially crafted filesystem image. Users should avoid processing ISO files from untrusted sources and apply security updates.
Azərbaycanca: CVE-2026-62423 libfsimage kitabxanasının iso9660 sürücüsündə kataloq keçidi zamanı bir neçə uzunluğun diskin idarə olunan sahələrindən birbaşa götürüldüyü, lakin yoxlanılmadığı zəiflikdir. Zəiflikdən müvəffəqiyyətlə istifadə hücumçuya xüsusi hazırlanmış fayl sistemi obrazı vasitəsilə oxuma/yazma əməliyyatlarını manipulyasiya etməyə imkan verə bilər. İstifadəçilərə etibarsız mənbələrdən gələn ISO fayllarını emal etməmək və təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
In which library and its which driver was the CVE-2026-62423 vulnerability discovered?
The CVE-2026-62423 vulnerability was discovered in the iso9660 driver of the libfsimage library.
What recommendations should users follow to protect themselves from the CVE-2026-62423 vulnerability?
Users should avoid processing ISO files from untrusted sources and apply security updates.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.