PT-2026-40361 · Nanazip · Nanazip

Jarlob

·

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-44215

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions NanaZip versions 5.0.1252.0 through 6.0.1697.0
Description A one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesystem image parser. This occurs when opening a specially crafted UFS filesystem image, allowing an attacker to control the byte offset of the write within a approximately 254-byte window beyond the heap allocation boundary.
Recommendations Update to version 6.0.1698.0.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-44215

Affected Products

Nanazip