CVE-2026-62423: Iso9660 Susp Missing Length Validation
Missing length validation when processing Rock Ridge SUSP records. The record length is used but not validated against the minimum record size (4 bytes) or the remaining buffer space, which can lead to boundary check bypasses, infinite loops, or CPU exhaustion.
greprules fetch cve-2026-62423-iso9660-susp-missing-length-validation --engine opengrepDescription
Missing length validation when processing Rock Ridge SUSP records. The record length is used but not validated against the minimum record size (4 bytes) or the remaining buffer space, which can lead to boundary check bypasses, infinite loops, or CPU exhaustion.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.