Integer Divide-By-Zero Vulnerability in NanaZip by M2Team
CVE-2026-42443

3.3LOW

Key Information:

Vendor

M2team

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-42443?

NanaZip, an open-source file archiving tool, contains a vulnerability in its UFS/UFS2 filesystem image parser, affecting versions from 5.0.1252.0 up to 6.0.1697.9. This issue occurs due to the lack of validation when processing a crafted UFS image with a superblock field fs_ipg set to zero. As a result, the application attempts to use this controlled value as a divisor, leading to an immediate crash and hardware trap. The vulnerability has been addressed in version 6.0.1698.0 and poses risks to users operating on affected versions.

Affected Version(s)

NanaZip >= 5.0.1250.0, < 6.0.1698.0

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.