# 7-Zip NTFS Handler Heap Overflow CVE-2026-48095 — vtable Hijack via Crafted Archive (GHSL-2026-140)

> A heap buffer overflow in 7-Zip versions through 26.00 (CVE-2026-48095, GHSL-2026-140) lets attackers achieve arbitrary code execution by tricking a user into opening a crafted NTFS image. A shift-overflow defect in CInStream::GetCuSize() (NtfsHandler.cpp:687) allocates a 1-byte _inBuf that is then overwritten with up to 256 MB of attacker-controlled data, corrupting the adjacent CInStream object's vtable and yielding a classic vtable hijack on both 32-bit and 64-bit builds. The NTFS handler's signature-based fallback means the bug is reachable regardless of file extension (.7z, .zip, .rar, or none).

- **Published:** 2026-05-26T00:00:00Z
- **Last reviewed:** 2026-05-26T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0586
- **ID:** TL-2026-0586
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-48095

## Description

CVE-2026-48095 (GitHub Security Lab advisory GHSL-2026-140) is a heap buffer overflow in the NTFS handler of 7-Zip versions through 26.00 that leads to arbitrary code execution via vtable hijacking. The flaw was responsibly disclosed by Jaroslav Lobačevski (@JarLob) of the GitHub Security Lab and confirmed using UBSan (UndefinedBehaviorSanitizer) under Clang on Linux x64.

Root cause: The function CInStream::GetCuSize() in CPP/7zip/Archive/Ntfs/NtfsHandler.cpp (line 687) computes the NTFS compression-unit buffer size with the expression (UInt32)1 << (BlockSizeLog + CompressionUnit). When an attacker-crafted NTFS image sets ClusterSizeLog >= 28 — a value explicitly accepted by 7-Zip's parser — and the compressed-data attribute carries CompressionUnit == 4, the shift exponent reaches 32. A 32-bit shift of a 32-bit value is undefined behavior in C++. On x86/x64 hardware, the CPU silently masks the shift count to 5 bits, so the result is 1 instead of 0, and the buffer is allocated as a single byte via _inBuf.Alloc(1).

Exploit primitive: The undersized 1-byte _inBuf is then passed to a ReadStream_FALSE call that copies up to 256 MB of attacker-controlled cluster data into it. Because the adjacent CInStream object is placed only 304 bytes after _inBuf on the heap, the first 64 KB read iteration overwrites the object's vtable pointer with attacker-supplied bytes. The second iteration immediately dispatches a virtual call through the now-corrupted vtable, producing a clean vtable hijack with full attacker control over the indirect call target. On 64-bit systems with at least 16 GB RAM the preceding _outBuf.Alloc(8 GB) call succeeds and execution proceeds straight to the overflow; on lower-memory systems the allocation fails and the bug degrades to a denial-of-service.

Reachability and attack surface: 7-Zip's NTFS handler is registered with a signature-based fallback that matches the literal byte sequence 'NTFS    ' at offset 3 of the archive. As a result, the vulnerable handler is invoked regardless of file extension — a malicious NTFS image disguised as .7z, .zip, .rar, .iso, or with no extension at all will be parsed through the buggy path once the extension-matched handler rejects the file. The only required user interaction is opening the crafted file in 7-Zip (Explorer shell, 7zFM.exe GUI, or 7z.exe command-line all reach the same code path). This makes the bug suitable for phishing payloads, supply-chain artifacts, and watering-hole archive drops.

Classification: CWE-787 (Out-of-Bounds Write) and CWE-190 (Integer Overflow or Wraparound). CVSS 3.1 base score 8.8 (High), vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The flawed GetCuSize() computation has been present since NTFS compressed-stream support was first introduced in 7-Zip, so every 7-Zip release with NTFS support up to and including 26.00 is vulnerable. UBSan flagged the root-cause shift UB at NtfsHandler.cpp:687, followed by a cascading invalid vtable dereference resulting in SIGSEGV in the proof-of-concept crash.

No in-the-wild exploitation has been reported at disclosure time, but the public advisory contains sufficient technical detail (root-cause location, trigger conditions, heap layout, vtable corruption mechanic) for skilled adversaries to weaponize. Users should update 7-Zip to a patched build immediately and treat untrusted archive files of any extension as potentially malicious until the fix is deployed.

## MITRE ATT&CK

- T1566 Phishing
- T1566.001 Phishing: Spearphishing Attachment
- T1566.002 Phishing: Spearphishing Link
- T1189 Drive-by Compromise
- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1204.002 User Execution: Malicious File
- T1203 Exploitation for Client Execution
- T1059 Command and Scripting Interpreter
- T1036.005 Match Legitimate Resource Name or Location
- T1036.007 Masquerading: Double File Extension
- T1027.009 Obfuscated Files or Information: Embedded Payloads
- T1574 Hijack Execution Flow
- T1055 Process Injection
- T1547 Boot or Logon Autostart Execution
- T1068 Exploitation for Privilege Escalation
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1071.001 Application Layer Protocol: Web Protocols
- T1499 Endpoint Denial of Service

## Sources

- [New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems](https://cybersecuritynews.com/7-zip-vulnerabilities-code-execution/)
- [GitHub Security Lab Advisory GHSL-2026-140 (7-Zip NTFS Handler Heap Overflow)](https://securitylab.github.com/advisories/GHSL-2026-140-7-Zip/)
- [7-Zip Official Site — Releases and Source Code](https://www.7-zip.org/)
- [7-Zip Source Repository (CPP/7zip/Archive/Ntfs/NtfsHandler.cpp)](https://sourceforge.net/projects/sevenzip/)
- [CWE-787 Out-of-Bounds Write](https://cwe.mitre.org/data/definitions/787.html)
- [CWE-190 Integer Overflow or Wraparound](https://cwe.mitre.org/data/definitions/190.html)
- [NVD CVE-2026-48095](https://nvd.nist.gov/vuln/detail/CVE-2026-48095)
- [GitHub Security Lab — Jaroslav Lobačevski (@JarLob)](https://securitylab.github.com/research/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0586
