0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

7-Zip security update fixes heap-based buffer overflow in version 26.00 (heise.de)

· 61d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • CVE-2026-48095 with CVSS 8.8 in 7-Zip 26.00
  • Heap-based buffer overflow in NTFS stream processing
  • Code execution on 64-bit systems with ≥16 GB RAM
  • No auto-update; manual update to 26.01 required

"The GitHub Security Team discovered a vulnerability in 7-Zip 26.00 (CVE-2026-48095, CVSS 8.8). Attackers can trigger a heap-based buffer overflow via crafted archives, allowing arbitrary code execution. 32-bit systems are always affected; on 64-bit systems with at least 16 GB RAM, code execution is possible. The update to version 26.01, released April 27, 2026, fixes the issue. No auto-update mechanism exists; users must update manually."

Discussion Matrix

0 segments

no comments yet.