7-Zip security update fixes heap-based buffer overflow in version 26.00 (heise.de)
0xBASE INTEL BRIEF
- CVE-2026-48095 with CVSS 8.8 in 7-Zip 26.00
- Heap-based buffer overflow in NTFS stream processing
- Code execution on 64-bit systems with ≥16 GB RAM
- No auto-update; manual update to 26.01 required
"The GitHub Security Team discovered a vulnerability in 7-Zip 26.00 (CVE-2026-48095, CVSS 8.8). Attackers can trigger a heap-based buffer overflow via crafted archives, allowing arbitrary code execution. 32-bit systems are always affected; on 64-bit systems with at least 16 GB RAM, code execution is possible. The update to version 26.01, released April 27, 2026, fixes the issue. No auto-update mechanism exists; users must update manually."
no comments yet.