From 0e82c89dfd11ed95cab56c41d1ac5518beb934ec Mon Sep 17 00:00:00 2001 From: tonghuaroot Date: Wed, 27 May 2026 20:12:52 +0800 Subject: [PATCH] NtfsHandler: backport 7-Zip 26.01 ClusterSizeLog bound (CVE-2026-48095) Upstream 7-Zip 26.01 tightened the ClusterSizeLog cap in the NTFS boot-sector parser from > 30 to > 21 so the shift exponent in GetCuSize() (BlockSizeLog + CompressionUnit, max +4) cannot reach 32 on a malicious image. With the prior > 30 bound the 32-bit shift was undefined behaviour and reduced the compression-unit buffer to 1 byte before a 256 MiB write followed. Disclosed as CVE-2026-48095. Signed-off-by: tonghuaroot --- CPP/7zip/Archive/NtfsHandler.cpp | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CPP/7zip/Archive/NtfsHandler.cpp b/CPP/7zip/Archive/NtfsHandler.cpp index 7d0c6f780..2c8fe8104 100644 --- a/CPP/7zip/Archive/NtfsHandler.cpp +++ b/CPP/7zip/Archive/NtfsHandler.cpp @@ -120,7 +120,7 @@ bool CHeader::Parse(const Byte *p) return false; sectorsPerClusterLog = t; ClusterSizeLog = SectorSizeLog + sectorsPerClusterLog; - if (ClusterSizeLog > 30) + if (ClusterSizeLog > 21) return false; }