Junglewise Threat Intelligence

CVE-2026-48104: 7-Zip uninitialized heap read in SquashFS handler

CVE-2026-48104 · Severity: medium · CVSS 4.2 · Published 2026-06-05

Technologies: Igor Pavlov 7-Zip.

Executive brief

7-Zip is a widely used file archiving utility. A vulnerability in its SquashFS file handler allows a specially crafted archive to cause the application to crash or potentially leak small amounts of memory from the computer's temporary storage. This occurs automatically when a user attempts to open a malicious file, potentially leading to a denial of service or minor data exposure.

Technical details

An uninitialized heap read exists in the SquashFS handler due to a sparsely populated index array (_blockToNode). When processing a crafted SquashFS image where inodes span many blocks, the array contains uninitialized POD storage from the heap. During the Open() operation, the OpenDir function uses attacker-influenced indices to perform a binary search over these uninitialized values. This can result in a chained out-of-bounds (OOB) read primitive. While the vulnerability is triggered simply by opening a file, successful exploitation is highly dependent on heap layout and is not reliably triggerable. The issue is fixed in version 26.01.

Affected products

  • Igor Pavlov 7-Zip 9.18 through 26.00

Timeline

  • 2026-04-21: disclosed: Reported to vendor via SourceForge private issues
  • 2026-04-27: patched: Version 26.01 released with fixes
  • 2026-06-05: advisory: CVE-2026-48104 published