DEBIAN-CVE-2026-48103

Source
https://security-tracker.debian.org/tracker/CVE-2026-48103
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48103.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-48103
Upstream
  • CVE-2026-48103
Published
2026-06-05T17:16:48Z
Modified
2026-09-14T17:03:16Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H CVSS Calculator
Summary
[none]
Details

7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain an off-by-one heap out-of-bounds read in the WIM (Windows Imaging) archive handler's security descriptor lookup. In CHandler::GetSecurity (CPP/7zip/Archive/Wim/WimHandler.cpp), the per-image SecurOffsets table holds numEntries + 1 cumulative offsets, but the check securityId >= SecurOffsets.Size() admits securityId == numEntries, and the function then reads SecurOffsets[securityId + 1], fetching one UInt32 past the end of the heap-allocated CRecordVector (which performs no bounds checking on operator[]). The securityId is attacker-controlled at offset +0xC of any directory entry in WIM metadata, and the handler is registered for .wim, .swm, .esd, and .ppkg and enabled by default in stock 7z.dll; the OOB triggers zero-click in the GUI because 7zFM.exe's ListView calls GetRawProp(kpidNtSecure) for every item during listing (ASan-confirmed), and is also reachable via CLI listing with 7zz l -slt. Impact is limited to denial of service under hardened allocators and minor information disclosure, since the OOB value is only consumed arithmetically as a length and is not surfaced to the attacker; there is no write primitive.

References

Affected packages

Debian:12 / 7zip

Package

Name
7zip
Purl
pkg:deb/debian/7zip?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
22.01+really26.01+dfsg-0+deb12u1

Affected versions

22.*
22.01+dfsg-8
22.01+dfsg-8+deb12u1
22.01+dfsg-9
22.01+dfsg-10~exp1
22.01+really25.01+dfsg-0+deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48103.json"

Debian:13 / 7zip

Package

Name
7zip
Purl
pkg:deb/debian/7zip?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

24.*
24.09+dfsg-8
25.*
25.00+dfsg-1
25.01+dfsg-1~deb13u1~bpo12+1
25.01+dfsg-1~deb13u1
25.01+dfsg-1~deb13u2
25.01+dfsg-1
25.01+dfsg-2
25.01+dfsg-3
25.01+dfsg-4
25.01+dfsg-5
26.*
26.00+dfsg-1
26.00+dfsg-2
26.00+dfsg-3
26.00+dfsg-4
26.00+dfsg-5
26.00+dfsg1-1
26.00+dfsg1-2
26.00+dfsg1-3
26.01+dfsg-1
26.01+dfsg-2
26.01+dfsg-3
26.02+dfsg-1
26.02+dfsg-2
26.02+dfsg-3
26.03+dfsg-1
26.03+dfsg-2
26.03+dfsg-3

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48103.json"

Debian:14 / 7zip

Package

Name
7zip
Purl
pkg:deb/debian/7zip?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.01+dfsg-1

Affected versions

24.*
24.09+dfsg-8
25.*
25.00+dfsg-1
25.01+dfsg-1~deb13u1~bpo12+1
25.01+dfsg-1~deb13u1
25.01+dfsg-1~deb13u2
25.01+dfsg-1
25.01+dfsg-2
25.01+dfsg-3
25.01+dfsg-4
25.01+dfsg-5
26.*
26.00+dfsg-1
26.00+dfsg-2
26.00+dfsg-3
26.00+dfsg-4
26.00+dfsg-5
26.00+dfsg1-1
26.00+dfsg1-2
26.00+dfsg1-3

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48103.json"

Debian:12 / p7zip

Package

Name
p7zip
Purl
pkg:deb/debian/p7zip?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
16.02+really26.01+dfsg-0+deb12u1

Affected versions

16.*
16.02+dfsg-8
16.02+really25.01+dfsg-0+deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48103.json"

Debian:13 / p7zip

Package

Name
p7zip
Purl
pkg:deb/debian/p7zip?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
16.02+transitional.1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48103.json"