Skip to content
CVE-2026-102514 ·
High · October 1, 2026

Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archive

S0
Secur0 CNA
CVE-2026-102514

Description

Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier, which allows an attacker who convinces a victim to open or extract a crafted .pea archive to execute arbitrary code as the user running PeaZip. While decompressing a PCOMPRESS1 stream, the 32-bit compressed-block-size field of the first block (compsize) is read directly from the archive at pea.pas:3790 and used without validation as the length of a blockread into the fixed-size global buffers wbuf1/wbuf2 (1,114,112 bytes each, declared at pea.pas:462) and as the bound of the subsequent copy loop. The existing check if compsize > WBUFSIZE then internal_error(...) is applied only to the size of each following block at pea.pas:3849, so the first block escapes it entirely; the same unvalidated value is also used to index wbuf1[compsize] at the same line, producing an out-of-bounds read at an attacker-chosen offset. The copy loop at pea.pas:3815 additionally copies the requested length i instead of the number of bytes actually read (numread), and terminates on equality (if addr = compsize+4) rather than on an upper bound, so an overshoot leaves the condition permanently unsatisfiable. Because the project is built without range checking ({$R-} by default, confirmed by the absence of <RangeChecks> in project_pea.lpi) and no archive password, integrity tag or non-default configuration is required to reach the vulnerable path, the overflow overwrites adjacent global data deterministically. Code execution was demonstrated independently by two researchers against the official Linux x86_64 and Windows x64 builds; the out-of-bounds write is cross-platform (Windows, macOS, Linux, BSD).

Vulnerability type (CWE)

CWE-787: Out-of-bounds Write

CWE-1284: Improper Validation of Specified Quantity in Input

CWE-125: Out-of-bounds Read

Affected versions

All versions of PeaZip prior to 11.3.0. The vulnerable code is traceable to the original PEA component (pea 0.10, 15/09/2006). Default status: affected.

Score (CVSS 4.0)

High (8.4)

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Solution

Upgrade to PeaZip 11.3.0 or higher. The fix validates the size of the first compressed block before using it as a read length, copies the number of bytes actually read (numread) instead of the requested length, and stops the block-reading loop when the running offset exceeds the expected value.

Patch

Commit 90ddbaee0945a4d8ffa4d972d43711bbfb9576ba

Credits

  • julichaan - finder
  • c4sh3r - finder
  • Darío Rivas Quero - analyst
  • Secur0 CNA - coordinator

Discovery source: External

Official record: CVE-2026-102514