PT-2026-46982 · 7 Zip+1 · 7-Zip
CVE-2026-48112
·
Published
2026-04-21
·
Updated
2026-08-13
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
7-Zip versions 9.18 through 26.00
Description
A heap out-of-bounds read exists in the Unix ar archive parser within the BSD SYMDEF parser. When parsing a BSD-style
.SYMDEF symbol table, the ParseLibSymbols() function uses Get32 to read a 32-bit namesSize field. If the position equals the buffer size, the system reads 4 bytes past the end of the heap allocation, which results in reading uninitialized heap data under the default allocator.Recommendations
Update to version 26.01.
Fix
DoS
Integer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
7-Zip