Executive brief
NanaZip is a file archiving utility for Windows based on the 7-Zip project. A security flaw in how it handles LVM disk image files could allow an attacker to crash the application or potentially leak small amounts of information if a user is tricked into opening a specially crafted file. This occurs because the software fails to properly verify the size of certain data before reading it, which can lead to a system crash or service disruption.
Technical details
A heap buffer-overflow read exists in the LVM2 physical-volume metadata parser within NanaZip's LvmHandler (inherited from upstream 7-Zip but specifically enabled in NanaZip). The vulnerability is rooted in the CHandler::Open2 function in LvmHandler.cpp, where the code allocates a buffer based on an attacker-controlled size field but performs a CRC-32 check using a hardcoded length of 508 bytes. If the allocated size is less than 512 bytes, the CRC calculation reads past the end of the heap allocation. While 7-Zip contains the vulnerable code, it is not affected in its default builds because the LVM handler is disabled; NanaZip is vulnerable because it explicitly enables this handler. Attackers can trigger this by providing a malformed .lvm file, leading to a denial-of-service (crash) or a side-channel information leak via the CRC matching result.
Affected products
- M2Team NanaZip 3.0.1000.0 to before 6.0.1698.0
Timeline
- 2026-05-18: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: NVD publication date