GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip
A heap buffer overflow vulnerability (GHSL-2026-140) exists in 7-Zip version 26.00, caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to exploit this issue for arbitrary code execution or application crashes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
7-Zipto a version that resolves this vulnerability.Fixed in 26.00Patch GHSL-2026-140
Event History
Frequently Asked Questions
What is the severity of GHSL-2026-140?
The severity of GHSL-2026-140 is rated at 77, indicating a high risk level.
How do I fix GHSL-2026-140?
To mitigate GHSL-2026-140, update 7-Zip to the latest version beyond 26.00 as soon as possible.
What causes the GHSL-2026-140 vulnerability?
GHSL-2026-140 is caused by an under-allocation in the NTFS compressed stream buffer, leading to a heap buffer overflow.
What are the potential impacts of GHSL-2026-140?
Exploiting GHSL-2026-140 may allow attackers to execute arbitrary code on affected systems.
Which version of 7-Zip is affected by GHSL-2026-140?
GHSL-2026-140 affects 7-Zip version 26.00.