CVE-2026-48102
Published: June 5th, 2026
7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF disc image handler's File Identifier Descriptor parser. In CFileId::Parse (CPP/7zip/Archive/Udf/UdfIn.cpp), after validating size < 38 + idLen + impLen and advancing processed to 38 + impLen + idLen, the alignment-padding loop reads p[processed] while incrementing up to 3 times to reach a 4-byte boundary, and the processed <= size bounds check only runs after the loop. When (38 + impLen + idLen) % 4 != 0 and 38 + impLen + idLen == size, the loop reads 1 to 3 bytes past the end of the exact-size heap buffer allocated via buf.Alloc((size_t)item.Size). The UDF handler is registered for .iso and .udf files and auto-detected by signature, and the OOB read triggers during Open() when listing or extracting a crafted UDF image. Impact is limited to information disclosure (a 1-bit oracle per OOB byte via open/fail behavior) and denial of service (crash under hardened allocators); there is no write primitive. Version 26.01 fixes the issue.
LOW
CVSS v3: 3.1
CVSS v3: 3.1
Status
| DocFilters Release | Package | State | Justification | Comment |
|---|---|---|---|---|
| 26.3 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 26.2 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 26.1 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 25.4 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 25.3 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 25.2 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 25.1 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 24.4 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 24.4.0 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 24.3 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 24.2 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 24.1 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 23.3 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 23.2 | 7-zip (17.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 23.1 | 7-zip (17.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
| 22.4 | 7-zip (17.01) | Not Affected | Code Not Present | The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters. |
Severity score breakdown
Attack Complexity
HIGH
Attack Vector
NETWORK
Availability Impact
NONE
Base Score
3.1
Base Severity
LOW
Confidentiality Impact
LOW
Integrity Impact
NONE
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Version
3.1