CVE-2026-42442
EUVD-2026-2978712.05.2026, 20:16
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS image where the root inode (inode 2) is set to IFLNK (symlink) instead of IFDIR (directory). The parser unconditionally treats the root inode as a directory without checking its type, and when the symlink has an embedded target (small di_size), the directory data buffer is zero-length, causing a null-pointer dereference on the first read. This vulnerability is fixed in 6.0.1698.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| m2team | nanazip | 5.0.1250.0 ≤ 𝑥 < 6.0.1698.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration