CVE-2026-48095: CWE-787: Out-of-bounds Write in mcmilk 7-Zip
CVE-2026-48095 is a heap buffer overflow vulnerability in 7-Zip versions 26. 00 and earlier, caused by an under-allocation in the NTFS compressed stream buffer. This flaw allows crafted NTFS images with specific parameters to trigger an out-of-bounds write, potentially leading to arbitrary code execution or application crashes. The vulnerability arises from undefined behavior in buffer size calculation, resulting in a 1-byte allocation overwritten by up to 256 MB of data. The NTFS handler is enabled by default and processes files based on signature fallback, making the attack possible regardless of file extension. Version 26. 01 of 7-Zip addresses this issue. The vulnerability has a high severity with a CVSS score of 8. 8.
AI Analysis
Technical Summary
7-Zip versions up to 26.00 contain a heap buffer overflow in the NTFS handler due to an under-allocation in the compressed stream buffer size calculation (CInStream::GetCuSize). When processing a crafted NTFS image with ClusterSizeLog >= 28 and CompressionUnit == 4, the exponent calculation overflows, causing the buffer _inBuf to be allocated as 1 byte. Subsequent writes of up to 256 MB overflow this buffer and overwrite adjacent memory, including the CInStream object's vtable pointer, enabling vtable hijacking and potential arbitrary code execution. On 32-bit builds, the overflow is unconditional; on 64-bit builds, it depends on a large parallel buffer allocation. The NTFS handler is enabled by default and triggered by signature-based fallback, allowing exploitation regardless of file extension. The issue is fixed in version 26.01.
Potential Impact
Successful exploitation can lead to arbitrary code execution or application crashes due to heap buffer overflow and vtable pointer overwrite. This affects confidentiality, integrity, and availability of the affected system. The vulnerability can be triggered by processing crafted NTFS images during extraction or testing in 7-Zip. The CVSS score of 8.8 reflects high impact with network attack vector, low attack complexity, no privileges required, and user interaction needed.
Mitigation Recommendations
Version 26.01 of 7-Zip fixes this vulnerability. Users should upgrade to 7-Zip 26.01 or later to remediate the issue. No official patch or temporary fix details are provided beyond this version update. Until upgrading, avoid opening or extracting files from untrusted sources that may contain crafted NTFS images. Patch status is not explicitly confirmed beyond the version update note; users should verify with the vendor advisory for the latest remediation guidance.
CVE-2026-48095: CWE-787: Out-of-bounds Write in mcmilk 7-Zip
Description
CVE-2026-48095 is a heap buffer overflow vulnerability in 7-Zip versions 26. 00 and earlier, caused by an under-allocation in the NTFS compressed stream buffer. This flaw allows crafted NTFS images with specific parameters to trigger an out-of-bounds write, potentially leading to arbitrary code execution or application crashes. The vulnerability arises from undefined behavior in buffer size calculation, resulting in a 1-byte allocation overwritten by up to 256 MB of data. The NTFS handler is enabled by default and processes files based on signature fallback, making the attack possible regardless of file extension. Version 26. 01 of 7-Zip addresses this issue. The vulnerability has a high severity with a CVSS score of 8. 8.
CVSS v3.1
Score 8.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
7-Zip versions up to 26.00 contain a heap buffer overflow in the NTFS handler due to an under-allocation in the compressed stream buffer size calculation (CInStream::GetCuSize). When processing a crafted NTFS image with ClusterSizeLog >= 28 and CompressionUnit == 4, the exponent calculation overflows, causing the buffer _inBuf to be allocated as 1 byte. Subsequent writes of up to 256 MB overflow this buffer and overwrite adjacent memory, including the CInStream object's vtable pointer, enabling vtable hijacking and potential arbitrary code execution. On 32-bit builds, the overflow is unconditional; on 64-bit builds, it depends on a large parallel buffer allocation. The NTFS handler is enabled by default and triggered by signature-based fallback, allowing exploitation regardless of file extension. The issue is fixed in version 26.01.
Potential Impact
Successful exploitation can lead to arbitrary code execution or application crashes due to heap buffer overflow and vtable pointer overwrite. This affects confidentiality, integrity, and availability of the affected system. The vulnerability can be triggered by processing crafted NTFS images during extraction or testing in 7-Zip. The CVSS score of 8.8 reflects high impact with network attack vector, low attack complexity, no privileges required, and user interaction needed.
Mitigation Recommendations
Version 26.01 of 7-Zip fixes this vulnerability. Users should upgrade to 7-Zip 26.01 or later to remediate the issue. No official patch or temporary fix details are provided beyond this version update. Until upgrading, avoid opening or extracting files from untrusted sources that may contain crafted NTFS images. Patch status is not explicitly confirmed beyond the version update note; users should verify with the vendor advisory for the latest remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T18:40:45.834Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a22e1c9e29bf47b508136c6
Added to database: 6/5/2026, 2:48:41 PM
Last enriched: 6/5/2026, 3:03:56 PM
Last updated: 6/5/2026, 4:53:23 PM
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.