Heap Out-of-Bounds Vulnerability in NanaZip File Archive Software
CVE-2026-44215
4.4MEDIUM
What is CVE-2026-44215?
NanaZip, an open-source file archiving tool, is susceptible to a heap out-of-bounds vulnerability that can be exploited when opening a specially crafted UFS filesystem image. This flaw allows an attacker to modify byte offsets within a 254-byte range beyond the allocated memory heap. This can potentially lead to unauthorized access or disruption in software functionality. Users are advised to update to version 6.0.1698.0 or later, which addresses this security issue.
Affected Version(s)
NanaZip >= 5.0.1250.0, < 6.0.1698.0
