PT-2026-46970 · 7 Zip+1 · 7-Zip

CVE-2026-48101

·

Published

2026-04-21

·

Updated

2026-08-13

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions 7-Zip versions 9.21 through 26.00
Description An uninitialized memory disclosure exists in the UEFI capsule (.scap) parser. The OpenCapsule() function allocates a heap buffer based on an attacker-declared CapsuleImageSize (up to 1 GiB) without zero-initialization. The system then reads file contents into this buffer using ReadStream FALSE(), but the return value is discarded. If the file is truncated, the remaining part of the buffer retains uninitialized heap memory, which is subsequently exposed as extracted file content through GetStream().
Recommendations Update to version 26.0.1.

Fix

DoS

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07869
CVE-2026-48101
ECHO-7B47-8F62-C1EF
OPENSUSE-SU-2026:11502-1
OPENSUSE-SU-2026:21038-1
SUSE-SU-2026:22347-1
SUSE-SU-2026:2696-1

Affected Products

7-Zip