Out-of-Bounds Write Vulnerability in PeaZip by PeaZip Developers
CVE-2026-102514
What is CVE-2026-102514?
An out-of-bounds write vulnerability has been identified in the PeaZip archive extraction routine. This flaw allows an attacker to manipulate a specially crafted .pea archive, potentially allowing for arbitrary code execution when the victim decompresses it. The vulnerability arises from an improper check on the size of the compressed block, leading to unvalidated memory access. As a result, an attacker can exploit the application to overwrite critical memory areas, leading to memory corruption and denial-of-service conditions across different platforms, including Windows, macOS, Linux, and BSD. Users are encouraged to update to the latest version of PeaZip to mitigate the risks associated with this vulnerability.
Affected Version(s)
PeaZip Windows 0 < 11.3.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
