Junglewise Threat Intelligence

CVE-2026-48101: 7-Zip uninitialized memory disclosure in UEFI capsule parser

CVE-2026-48101 · Severity: medium · CVSS 6.5 · Published 2026-06-05

Technologies: 7-Zip. Vendors: 7-Zip.

Executive brief

7-Zip is a widely used file archiving utility for compressing and decompressing data. A security flaw in how it handles UEFI capsule (.scap) files allows a specially crafted archive to trick the program into exposing sensitive information from the computer's memory. This could result in private data from other applications or the system being leaked into the files extracted by the user.

Technical details

An uninitialized memory disclosure vulnerability exists in the UEFI capsule (.scap) parser of 7-Zip. The 'OpenCapsule' function allocates a heap buffer based on an attacker-controlled 'CapsuleImageSize' (up to 1 GiB) without zero-initialization. It then attempts to populate this buffer using 'ReadStream_FALSE'; however, the return value of this read operation is ignored. If the provided file is truncated, the unread portion of the buffer remains populated with stale heap memory. This uninitialized data is subsequently exposed to the user as extracted file content via 'GetStream'. The vulnerability is addressed in version 26.0.1.

Affected products

  • 7-Zip 7-Zip 9.21 through 26.00

Timeline

  • 2026-04-21: disclosed: Reported via SourceForge private issues
  • 2026-04-27: patched: Version 26.01 released with fixes
  • 2026-06-05: advisory: NVD publication date

Related threats