Bzip2 Project maintains a compression library that is embedded across Unix/Linux systems, archiving tools, and embedded applications despite its narrow product scope, making individual flaws potentially high-impact across downstream consumers. The observed vulnerability exposure centers on integer overflow and wraparound conditions within the compression engine, reflecting the arithmetic-intensive nature of data-format parsing. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bzip2 Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22895HIGH The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the http | Jan 10, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bzip2 Project.
Media articles that mention a CVE ID that affects a product developed by Bzip2 Project — matched by CVE ID, not by vendor name.