Description
Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier allows an attacker who convinces a victim to open or extract a crafted .pea archive to execute arbitrary code as the user running PeaZip. While decompressing a PCOMPRESS1 stream, the 32-bit compressed-block-size field of the first block (compsize) is read directly from the archive and used without validation as the length of a blockread into the fixed-size global buffers wbuf1/wbuf2 (1,114,112 bytes) and as the bound of the subsequent copy loop. The existing check "compsize > WBUFSIZE" is applied only to the size of each following block, so the first block escapes it; the same unvalidated value is also used to index wbuf1[compsize], an out-of-bounds read at an attacker-chosen offset. The copy loop additionally copies the requested length instead of the number of bytes actually read, and terminates on equality rather than on an upper bound. Because the project is built without range checking and no archive password, integrity tag or non-default configuration is required, the overflow overwrites adjacent global data; code execution was demonstrated by two independent researchers against the official Linux x86-64 and Windows x64 builds, and the denial-of-service and memory-corruption primitive is cross-platform (Windows, macOS, Linux, BSD).
Published: 2026-10-01
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: Arbitrary code execution via crafted .pea archive
Action: Immediate Patch
AI Analysis

Impact

PeaZip’s PEA extraction routine has an out‑of‑bounds write that lets an attacker, by convincing a user to open or extract a specially crafted .pea file, execute arbitrary code as the user running PeaZip. The vulnerability is triggered during decompression of the first PCOMPRESS1 block, where the 32‑bit compressed‑block‑size field is read directly from the file and used as the length to fill fixed‑size global buffers without validation. The overflow can overwrite adjacent global data, and researchers demonstrated code execution on official Linux x86‑64 and Windows x64 builds, confirming the impact across multiple platforms with no extra configuration or password required.

Affected Systems

The flaw is present in PeaZip 11.2.0 and earlier versions. It affects all supported operating systems, including Windows, macOS, Linux, and BSD, and applies to any user who opens or extracts a malicious .pea archive with these versions.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity flaw, and the EPSS is currently not available, so the exact likelihood of exploitation is unknown, but the vulnerability is listed as a serious risk. It is not part of the CISA KEV catalog. The attack vector is local, relying on social engineering or a user who knowingly opens a malicious archive; the attacker can achieve full code execution as the running user and potentially compromise the entire system. Because the bug involves an unchecked out‑of‑bounds write and copy loop, it can be exploited without additional privileges or exotic conditions.

Generated by OpenCVE AI on October 1, 2026 at 21:19 UTC.

Remediation

Vendor Solution

Upgrade to PeaZip 11.3.0 or higher, which validates the size of the first compressed block (commit 90ddbae), copies the number of bytes actually read, and stops the block-reading loop when the address exceeds the expected value.


OpenCVE Recommended Actions

  • Upgrade PeaZip to version 11.3.0 or newer, which validates the first block size and stops the block‑reading loop when the address exceeds the expected value.
  • Disable or prohibit the extraction of .pea archives from untrusted sources until the application is updated, preventing the exploit from being triggered via social‑engineering attacks.
  • Use an alternative archive utility for handling .pea files on older systems, or quarantine such files until a patched PeaZip version is deployed.

Generated by OpenCVE AI on October 1, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Peazip
Peazip peazip
Vendors & Products Peazip
Peazip peazip

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier allows an attacker who convinces a victim to open or extract a crafted .pea archive to execute arbitrary code as the user running PeaZip. While decompressing a PCOMPRESS1 stream, the 32-bit compressed-block-size field of the first block (compsize) is read directly from the archive and used without validation as the length of a blockread into the fixed-size global buffers wbuf1/wbuf2 (1,114,112 bytes) and as the bound of the subsequent copy loop. The existing check "compsize > WBUFSIZE" is applied only to the size of each following block, so the first block escapes it; the same unvalidated value is also used to index wbuf1[compsize], an out-of-bounds read at an attacker-chosen offset. The copy loop additionally copies the requested length instead of the number of bytes actually read, and terminates on equality rather than on an upper bound. Because the project is built without range checking and no archive password, integrity tag or non-default configuration is required, the overflow overwrites adjacent global data; code execution was demonstrated by two independent researchers against the official Linux x86-64 and Windows x64 builds, and the denial-of-service and memory-corruption primitive is cross-platform (Windows, macOS, Linux, BSD).
Title Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archive
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Secur0

Published:

Updated: 2026-10-01T20:24:18.718Z

Reserved: 2026-09-29T11:56:57.709Z

Link: CVE-2026-102514

cve-icon Vulnrichment

Updated: 2026-10-01T20:24:14.360Z

cve-icon NVD

Status : Received

Published: 2026-10-01T21:17:18.307

Modified: 2026-10-01T21:17:18.307

Link: CVE-2026-102514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T23:45:14Z

Weaknesses