CVE 4.3 MEDIUM

NanaZip: Heap buffer-overflow read in NanaZip LVM metadata CRC check_CVE-2026-47224

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Description

NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap buffer-overflow read exists in the LVM2 physical-volume metadata parser in NanaZip (via the upstream 7-Zip LvmHandler). The vulnerability is triggered when opening a crafted LVM disk image. This issue has been patched in stable version 6.0.1698.0 and preview version 6.5.1742.0.

Basic Information

ID CVE-2026-47224
Source GitHub_M
Published Jun 12, 2026 at 16:57

Affected Product

Vendor M2Team
Product NanaZip
Version >= 3.0.1000.0, < 6.0.1698.0
Affected Versions M2Team NanaZip >= 3.0.1000.0, < 6.0.1698.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.