← العودة للجدول
CVE-2026-48095
CVE-2026-48095 — 7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior
📅 2026-06-05
🟠 High 🔥 No NVD DDoS Windows CVSS 8.8

📋 الوصف الكامل

7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)

💻 الأنظمة المتأثرة

7-Zip is a

⚠️ نوع التهديد

DDoS

🔗 CVE ID

CVE-2026-48095

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v26.00

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←