Out-of-bounds write in 7-Zip - CVE-2026-48095
Published: May 26, 2026
7-Zip
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in the NTFS archive handler when processing a crafted NTFS image containing a compressed stream. A remote attacker can trick the victim into opening a crafted file to execute arbitrary code.
User interaction is required to open the crafted image, and the issue is triggered during extraction or testing of a compressed file from the image.