漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GHSL-2026-117: 7-Zip UEFI Capsule uninitialized heap memory disclosure
Vulnerability Description
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCapsule function allocates a heap buffer of attacker-declared CapsuleImageSize (up to 1 GiB) without zero-initialization, then reads the file contents into it with ReadStream_FALSE whose return value is silently discarded. If the file is truncated, the unread tail of the buffer retains uninitialized heap memory, which is then exposed as extracted file content via GetStream. Version 26.0.1 fixes the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
对未经初始化资源的使用
Vulnerability Title
7-Zip 安全漏洞
Vulnerability Description
7-Zip是7-Zip开源的一个压缩软件。 7-Zip 9.21版本至26.00版本存在安全漏洞,该漏洞源于UEFI胶囊解析器中未初始化内存泄露,可能导致攻击者通过截断文件使未读取的堆缓冲区保留未初始化内存并暴露为提取文件内容。
CVSS Information
N/A
Vulnerability Type
N/A