Bzip3 is a compression utility with a narrow product footprint that nonetheless achieves prominence through deep embedding in software supply chains and deployment across a wide range of systems and applications. Its vulnerability profile centers on the compression algorithm implementation itself, with recurring exposure in memory-safety weaknesses—out-of-bounds reads and writes, and improper memory-buffer restrictions—that are characteristic of native-code parsers handling untrusted compressed input. Defenders should track this vendor's releases and inventory bundled or statically linked instances, since remediation typically depends on downstream rebuilds; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bzip3 Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29421HIGH An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an out-of-bounds write in bz3_decode_block. | Apr 6, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-29420MEDIUM An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is a crash caused by an invalid memmove in bz3_decode_block. | Apr 6, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-29419MEDIUM An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is a bz3_decode_block out-of-bounds read. | Apr 6, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-29416MEDIUM An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A bz3_decode_block out-of-bounds write can occur with a crafted archive because bzip3 does not follow the required proc | Apr 6, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-29417MEDIUM An issue was discovered in libbzip3.a in bzip3 1.2.2. There is a bz3_decompress out-of-bounds read in certain situations where buffers passed to bzip3 do not contain enough space t | Apr 6, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-29415MEDIUM An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedur | Apr 6, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-29418MEDIUM An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an xwrite out-of-bounds read. | Apr 6, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bzip3 Project.
Media articles that mention a CVE ID that affects a product developed by Bzip3 Project — matched by CVE ID, not by vendor name.