CVE-2026-27114: NanaZip has ROMFS Archive Infinite Loop
Published Feb 19, 2026
·Updated
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular NextOffset chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.
Affected Software
2 affected components
NanaZip NanaZip>=5.0.1252.0<6.0.1630.0
M2team Nanazip>=5.0.1252.0<6.0.1630.0
Event History
Feb 19, 2026
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
DescriptionWeakness
Data Sourced
via NVD·09:18 PM
DescriptionSeverityWeaknessAffected Software
Jun 4, 58123
Event
via FIRST·10:45 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-27114?
CVE-2026-27114 has been classified with a severity level that could potentially lead to denial of service due to an infinite loop.
2
How do I fix CVE-2026-27114?
To mitigate CVE-2026-27114, upgrade to NanaZip version 6.0.1630.0 or later.
3
What products are affected by CVE-2026-27114?
CVE-2026-27114 affects NanaZip versions between 5.0.1252.0 and 6.0.1630.0.
4
What is the nature of the vulnerability in CVE-2026-27114?
CVE-2026-27114 involves circular `NextOffset` chains that cause an infinite loop during the parsing of ROMFS archives.
5
Is CVE-2026-27114 a critical vulnerability?
While not necessarily classified as critical, CVE-2026-27114 can lead to significant disruptions, warranting immediate attention.