CVE-2026-48101
MEDIUMGHSL-2026-117: 7-Zip UEFI Capsule uninitialized heap memory disclosure
Title source: cnaDescription
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCapsule function allocates a heap buffer of attacker-declared CapsuleImageSize (up to 1 GiB) without zero-initialization, then reads the file contents into it with ReadStream_FALSE whose return value is silently discarded. If the file is truncated, the unread tail of the buffer retains uninitialized heap memory, which is then exposed as extracted file content via GetStream. Version 26.0.1 fixes the issue.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/
Scores
CVSS v3
6.5
EPSS
0.0040
EPSS Percentile
31.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-908
Status
published
Products (2)
7-zip/7-zip
9.21 - 26.01
mcmilk/7-Zip
>= 9.21, < 26.01
Published
Jun 05, 2026
Tracked Since
Jun 05, 2026