Domenica 26 Luglio 2026 08:37:53 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContattiLogin
ItalianoEnglish

#CVE-2026-14266


Un archivio attendibile può comunque mordere: la vulnerabilità XZ di 7-Zip e i rischi nascosti nell'estrazione

Pubblicato: 20 Luglio 2026 12:21Categoria: Vulnerabilità e gestione delle patchArea: Europe / RussiaAutore: SECURESPECTER

CVE-2026-14266 mostra come una semplice apertura di un archivio possa trasformarsi in un evento di corruzione della memoria quando al codice di decompressione viene chiesto di fidarsi di una struttura ostile.

When an Archive Parser Trips, the Blast Radius Can Reach the Desktop

Published: 17 July 2026 10:36Category: Vulnerabilities & Patch ManagementGeo: Europe / RussiaAuthor: NEONPALADIN

A reported heap overflow in 7-Zip’s XZ decompression path shows how a single malformed archive can turn routine file handling into a memory-safety problem with possible code execution consequences.

When an Archive Becomes a Trap: The 7-Zip XZ Overflow That Turns Compression Into Risk

Published: 17 July 2026 08:02Category: Vulnerabilities & Patch ManagementGeo: Europe / RussiaAuthor: NEONPALADIN

A heap buffer overflow in 7-Zip’s XZ handling shows how a familiar file format can still become an attack surface when parser code meets crafted input.