7-Zip XZ Decoder Overflow Could Let Crafted Archives Execute Code

1 min read
Source: The Hacker News
7-Zip XZ Decoder Overflow Could Let Crafted Archives Execute Code
Photo: The Hacker News
TL;DR Summary

A heap-based buffer overflow in 7-Zip’s XZ decoding pipeline (CVE-2026-14266) can trigger when processing crafted XZ data, allowing code execution within the 7-Zip process. The fix in 7-Zip 26.02 corrects how remaining buffer space is tracked to prevent out-of-bounds writes. It’s a local attack vector requiring the user to open the file, with Windows processes typically running under limited rights, mitigating potential impact. ZDI rates the flaw as High (7.0); as of July 20, 2026, no public PoC or exploitation in the wild is known. Users should manually update to 7-Zip 26.02 or later on all machines, since the patch was released before disclosure and won’t auto-install on stand-alone systems.

Share this article

Reading Insights

Total Reads

0

Unique Readers

23

Time Saved

2 min

vs 3 min read

Condensed

79%

525110 words

Want the full story? Read the original article

Read on The Hacker News