CVE-2026-48101

Published: June 5th, 2026
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCapsule function allocates a heap buffer of attacker-declared CapsuleImageSize (up to 1 GiB) without zero-initialization, then reads the file contents into it with ReadStream_FALSE whose return value is silently discarded. If the file is truncated, the unread tail of the buffer retains uninitialized heap memory, which is then exposed as extracted file content via GetStream. Version 26.0.1 fixes the issue.
MEDIUM
CVSS v3: 6.5

Status

DocFilters Release Package State Justification Comment
26.3 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
26.2 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
26.1 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
25.4 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
25.3 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
25.2 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
25.1 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
24.4 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
24.4.0 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
24.3 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
24.2 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
24.1 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
23.3 7-zip (23.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
23.2 7-zip (17.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
23.1 7-zip (17.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.
22.4 7-zip (17.01) Not Affected Code Not Present The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.

Severity score breakdown

Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
NONE
Base Score
6.5
Base Severity
MEDIUM
Confidentiality Impact
HIGH
Integrity Impact
NONE
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Version
3.1

References