CVE-2026-102514
Received Received - Intake

Out-of-Bounds Write in PeaZip PEA Archive Extraction

Vulnerability report for CVE-2026-102514, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Secur0

Description

Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier allows an attacker who convinces a victim to open or extract a crafted .pea archive to execute arbitrary code as the user running PeaZip. While decompressing a PCOMPRESS1 stream, the 32-bit compressed-block-size field of the first block (compsize) is read directly from the archive and used without validation as the length of a blockread into the fixed-size global buffers wbuf1/wbuf2 (1,114,112 bytes) and as the bound of the subsequent copy loop. The existing check "compsize > WBUFSIZE" is applied only to the size of each following block, so the first block escapes it; the same unvalidated value is also used to index wbuf1[compsize], an out-of-bounds read at an attacker-chosen offset. The copy loop additionally copies the requested length instead of the number of bytes actually read, and terminates on equality rather than on an upper bound. Because the project is built without range checking and no archive password, integrity tag or non-default configuration is required, the overflow overwrites adjacent global data; code execution was demonstrated by two independent researchers against the official Linux x86-64 and Windows x64 builds, and the denial-of-service and memory-corruption primitive is cross-platform (Windows, macOS, Linux, BSD).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
peazip peazip 11.2.0
peazip peazip to 11.2.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds write vulnerability in PeaZip 11.2.0 and earlier. When extracting a specially crafted .pea archive, an attacker can cause the program to write data beyond the intended memory buffer. This happens because the compressed block size from the archive is used without proper validation, leading to memory corruption. The flaw affects the first block in the archive and can result in arbitrary code execution.

Detection Guidance

This vulnerability involves an out-of-bounds write in PeaZip's PEA archive extraction routine. Detection requires monitoring for crashes or unusual behavior when extracting .pea archives. Check system logs for segmentation faults or memory corruption errors during archive operations. No specific commands are provided in the context.

Impact Analysis

If you use PeaZip 11.2.0 or earlier and open or extract a malicious .pea file, an attacker could execute arbitrary code on your system with the same permissions as your user account. This could allow them to install malware, steal data, or take control of your computer. The vulnerability is cross-platform and affects Windows, macOS, Linux, and BSD.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling arbitrary code execution on a victim's system through a crafted .pea archive. If exploited, it may lead to unauthorized access, data breaches, or data exfiltration, which are critical violations under these regulations.

Mitigation Strategies

Immediately stop using PeaZip 11.2.0 or earlier. Update to the latest version if a patch is available. Avoid opening or extracting .pea archives from untrusted sources. Disable or uninstall PeaZip until a fix is confirmed. Monitor vendor advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102514. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart