🛡️ CVE-2026-48095 on Alpine — 7zip
Description
7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)1 << (BlockSizeLog + CompressionUnit), and a crafted image with ClusterSizeLog >= 28 and CompressionUnit == 4 drives the exponent to 32, which is undefined behavior and collapses on x86/x64 so _inBuf is allocated as 1 byte. ReadStream_FALSE then writes up to 256 MB of attacker-controlled data into that 1-byte buffer in 64 KB iterations, and because the CInStream object sits only 304 bytes after _inBuf, its vtable pointer is overwritten and the next dispatched call achieves a vtable hijack. On 32-bit builds the overflow is unconditionally reached; on 64-bit it requires the parallel 8 GB _outBuf allocation to succeed, otherwise failing closed to denial of service. The NTFS handler is enabled by default in stock 7z.dll and, via signature-based fallback matching "NTFS " at offset 3, will open a crafted image regardless of file extension during extraction or testing. Version 26.01 fixes the issue.
Distribution advisory
This page covers CVE-2026-48095 as tracked by Alpine, for the package 7zip. The fix is available in version 26.01-r0; earlier versions remain affected.
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. A user must be tricked into taking some action. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.
Affected software
ALPINE-CVE-2026-48095 is recorded against 1 package.
- 7zip (fixed in 26.01-r0)
Timeline and source
Published on 5 June 2026 and last revised on 18 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
CVE-2026-48095 on other distributions
Each distribution ships its own build and its own fixed version. Pick the one you run:
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| 7zip | — | 26.01-r0 |
References
Similar Threats
- Unknown ALPINE-CVE-2026-48092
- Unknown ALPINE-CVE-2026-48101
- Unknown ALPINE-CVE-2026-48102
- Unknown ALPINE-CVE-2026-48103
- Unknown ALPINE-CVE-2026-48112
More ALPINE CVE 2026 advisories
Browse all of ALPINE CVE 2026 in the advisory index.
- ALPINE-CVE-2026-45232
- ALPINE-CVE-2026-45445
- ALPINE-CVE-2026-45446
- ALPINE-CVE-2026-45447
- ALPINE-CVE-2026-46483
- ALPINE-CVE-2026-46582
- ALPINE-CVE-2026-47729
- ALPINE-CVE-2026-48092
- ALPINE-CVE-2026-48101
- ALPINE-CVE-2026-48102
- ALPINE-CVE-2026-48103
- ALPINE-CVE-2026-48104
- ALPINE-CVE-2026-48111
- ALPINE-CVE-2026-48112
- ALPINE-CVE-2026-48142
- ALPINE-CVE-2026-48163
Site Security Check
Is 7zip part of your stack?
ALPINE-CVE-2026-48095 is rated CVSS 8.8 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.