PT-2026-40356 · Nanazip · Nanazip

CVE-2026-42442

·

Published

2026-05-12

·

Updated

2026-05-18

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NanaZip versions 5.0.1252.0 through 6.0.1697.0
Description A null-pointer dereference exists in the UFS/UFS2 filesystem image parser. This occurs when opening a specially crafted UFS image where the root inode (inode 2) is set to IFLNK (symlink) instead of IFDIR (directory). The parser treats the root inode as a directory without verifying its type. If the symlink contains an embedded target (small di size), the directory data buffer is created with zero length, leading to a null-pointer dereference during the first read operation.
Recommendations Update to version 6.0.1698.0.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42442
GHSA-8R4X-FX3W-PH77

Affected Products

Nanazip