CVE-2026-42484 Details
Description
A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted PKZIP hash file. The issue affects modules 17200, 17210, 17220, 17225, and 17230. When data_type_enum<=1, attacker-controlled hex data from a user-supplied hash string is decoded into a fixed-size buffer without proper input-length validation.
A heap-based buffer overflow vulnerability has been identified in the PKZIP hash parser of Hashcat version 7.1.2. This vulnerability allows an attacker to cause a denial-of-service or potentially execute arbitrary code by using a crafted PKZIP hash file. The issue arises in modules 17200, 17210, 17220, 17225, and 17230. The vulnerability occurs when the data_type_enum is less than or equal to 1, as the hex data from the user-supplied hash string is decoded into a fixed-size buffer without proper validation of the input length.
Users can upgrade to Hashcat version 7.1.3 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/sgInnora/107f2eb20367e47d58c911e38d56a91f | CISA-ADP | ExploitMitigationThird Party Advisory |
| https://gist.github.com/sgInnora/107f2eb20367e47d58c911e38d56a91f | [email protected] | ExploitMitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-787 | Out-of-bounds Write | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| hashcat hashcat | 7.1.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | New CVE Received | [email protected] |