§ Trackr.Live
Latest writing

Notes from Trackr.Live

The landing site for Trackr Services

Cyber Tools

CVE-2026-48095: One Undefined Shift, 256 MB Into 1 Byte, and the Signature Fallback That Means ‘.rar’ Doesn’t Save You

CVE-2026-48095 is a heap buffer overflow in 7-Zip’s NTFS handler reachable from any file extension because of signature-based fallback parsing. The fix shipped in 26.01 three days after the private report; public disclosure came 25 days later. PoC is public, the trigger is a one-line undefined shift, and the exploitable vtable sits 304 bytes from the overflow site. The patch is uncomplicated. The deployment surface isn’t.

·