Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archive
Description
Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier, which allows an attacker who convinces a victim to open or extract a crafted .pea archive to execute arbitrary code as the user running PeaZip. While decompressing a PCOMPRESS1 stream, the 32-bit compressed-block-size field of the first block (compsize) is read directly from the archive at pea.pas:3790 and used without validation as the length of a blockread into the fixed-size global buffers wbuf1/wbuf2 (1,114,112 bytes each, declared at pea.pas:462) and as the bound of the subsequent copy loop. The existing check if compsize > WBUFSIZE then internal_error(...) is applied only to the size of each following block at pea.pas:3849, so the first block escapes it entirely; the same unvalidated value is also used to index wbuf1[compsize] at the same line, producing an out-of-bounds read at an attacker-chosen offset. The copy loop at pea.pas:3815 additionally copies the requested length i instead of the number of bytes actually read (numread), and terminates on equality (if addr = compsize+4) rather than on an upper bound, so an overshoot leaves the condition permanently unsatisfiable. Because the project is built without range checking ({$R-} by default, confirmed by the absence of <RangeChecks> in project_pea.lpi) and no archive password, integrity tag or non-default configuration is required to reach the vulnerable path, the overflow overwrites adjacent global data deterministically. Code execution was demonstrated independently by two researchers against the official Linux x86_64 and Windows x64 builds; the out-of-bounds write is cross-platform (Windows, macOS, Linux, BSD).
Vulnerability type (CWE)
CWE-787: Out-of-bounds Write
CWE-1284: Improper Validation of Specified Quantity in Input
CWE-125: Out-of-bounds Read
Affected versions
All versions of PeaZip prior to 11.3.0. The vulnerable code is traceable to the original PEA component (pea 0.10, 15/09/2006). Default status: affected.
Score (CVSS 4.0)
High (8.4)
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Solution
Upgrade to PeaZip 11.3.0 or higher. The fix validates the size of the first compressed block before using it as a read length, copies the number of bytes actually read (numread) instead of the requested length, and stops the block-reading loop when the running offset exceeds the expected value.
Patch
Commit 90ddbaee0945a4d8ffa4d972d43711bbfb9576ba
Credits
- julichaan - finder
- c4sh3r - finder
- Darío Rivas Quero - analyst
- Secur0 CNA - coordinator
Discovery source: External
Official record: CVE-2026-102514