PT-2026-46982 · 7 Zip+1 · 7-Zip

CVE-2026-48112

·

Published

2026-04-21

·

Updated

2026-08-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions 7-Zip versions 9.18 through 26.00
Description A heap out-of-bounds read exists in the Unix ar archive parser within the BSD SYMDEF parser. When parsing a BSD-style .SYMDEF symbol table, the ParseLibSymbols() function uses Get32 to read a 32-bit namesSize field. If the position equals the buffer size, the system reads 4 bytes past the end of the heap allocation, which results in reading uninitialized heap data under the default allocator.
Recommendations Update to version 26.01.

Fix

DoS

Integer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07871
CVE-2026-48112
ECHO-2815-A409-45DA
OPENSUSE-SU-2026:11502-1
OPENSUSE-SU-2026:21038-1
SUSE-SU-2026:22347-1
SUSE-SU-2026:2696-1

Affected Products

7-Zip