Executive brief
NanaZip is an open-source file archiver used to compress and decompress various file formats. A flaw in how it handles certain filesystem image files (UFS/UFS2) allows a specially crafted file to crash the application immediately upon opening. While this does not lead to data theft, it can disrupt operations and cause a denial of service for users attempting to process malicious archives.
Technical details
An uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser within NanaZip's 'GetAllPaths' function. The function lacks a recursion depth limit and does not track visited inodes, allowing a crafted UFS image with a deep directory tree or an inode cycle to exhaust the thread stack. On Windows, this results in a STATUS_STACK_OVERFLOW exception and a deterministic process crash. The vulnerability is triggered at archive open time due to file associations. It has been remediated in version 6.0.1698.0 by implementing proper recursion safeguards.
Affected products
- M2Team NanaZip 5.0.1252.0 to before 6.0.1698.0
Timeline
- 2025-02-01: other: Vulnerability introduced in version 5.0.1250.0
- 2026-04-27: advisory: GitHub Security Advisory published
- 2026-05-12: disclosed: CVE-2026-42445 published
- 2026-05-12: patched: Fixed in version 6.0.1698.0