Heap-Based Buffer Overflow in Hashcat's PKZIP Hash Parser
CVE-2026-42484
9.8CRITICAL
What is CVE-2026-42484?
A significant vulnerability exists in the PKZIP hash parser of Hashcat v7.1.2, where a heap-based buffer overflow can occur due to improper input-length validation. When the data_type_enum is less than or equal to 1, attacker-controlled hex data from a user-supplied hash string can be decoded into a fixed-size buffer. This flaw permits attackers to potentially execute arbitrary code or cause a denial of service by supplying a specially crafted PKZIP hash file, impacting modules 17200, 17210, 17220, 17225, and 17230.
