Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102514— Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archive

Quick assessment

Affected
PeaZip PeaZip
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PeaZip 11.2.0 及更早版本中,第一方 pea 组件的 PEA 归档解包例程(pea.pas 中的 unpea_procedure)存在越界写入漏洞(CWE-787)。该漏洞允许攻击者诱使受害者打开或解压一个精心构造的 .pea 归档文件,从而以运行 PeaZip 的用户身份执行任意代码。 在解压 PCOMPRESS1 流时,第一个压缩块(compsize)的 32 位压缩块大小字段直接从归档文件中读取,并未经任何验证即被用作向固定大小的全局缓冲区 wbuf1/wbuf2(大小为 1,114,112 字节

CVSS 8.4 · High EPSS 0.13% · P2

Affected Version Matrix 1

VendorProduct Version RangeStatus
PeaZip PeaZip < 11.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102514

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archive
Source: CVE Program / CVE List V5
Vulnerability Description
Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier allows an attacker who convinces a victim to open or extract a crafted .pea archive to execute arbitrary code as the user running PeaZip. While decompressing a PCOMPRESS1 stream, the 32-bit compressed-block-size field of the first block (compsize) is read directly from the archive and used without validation as the length of a blockread into the fixed-size global buffers wbuf1/wbuf2 (1,114,112 bytes) and as the bound of the subsequent copy loop. The existing check "compsize > WBUFSIZE" is applied only to the size of each following block, so the first block escapes it; the same unvalidated value is also used to index wbuf1[compsize], an out-of-bounds read at an attacker-chosen offset. The copy loop additionally copies the requested length instead of the number of bytes actually read, and terminates on equality rather than on an upper bound. Because the project is built without range checking and no archive password, integrity tag or non-default configuration is required, the overflow overwrites adjacent global data; code execution was demonstrated by two independent researchers against the official Linux x86-64 and Windows x64 builds, and the denial-of-service and memory-corruption primitive is cross-platform (Windows, macOS, Linux, BSD).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PeaZip PeaZip 0 ~ 11.3.0 -

II. Public POCs for CVE-2026-102514

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102514

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-102514 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102514

No comments yet


Leave a comment