PatchSiren cyber security CVE debrief
CVE-2026-42443 M2team CVE debrief
CVE-2026-42443 is a local denial-of-service issue in NanaZip’s UFS/UFS2 filesystem image parser. A crafted UFS image can set the superblock field fs_ipg to zero, and the parser uses that value as a divisor without validation, causing an immediate divide-by-zero trap and process crash. The issue is fixed in NanaZip 6.0.1698.0.
- Vendor
- M2team
- Product
- Nanazip
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-18
Who should care
NanaZip users and administrators, especially on systems that open untrusted UFS/UFS2 images or automate archive and disk-image inspection.
Technical summary
According to the NVD record and linked vendor advisory, NanaZip versions from 5.0.1252.0 to before 6.0.1698.0 contain an integer divide-by-zero in the UFS/UFS2 filesystem image parser. The trigger is a crafted UFS image whose superblock field fs_ipg (inodes per cylinder group) is set to zero. NVD maps the issue to CWE-369 and the listed CVSS vector indicates local access with user interaction and low availability impact only.
Defensive priority
Low. Patch promptly if NanaZip is present on endpoints that may open untrusted UFS images, but this is a crash-only issue with no listed confidentiality or integrity impact.
Recommended defensive actions
- Upgrade NanaZip to 6.0.1698.0 or later.
- Restrict or review handling of untrusted UFS/UFS2 disk images until patched.
- If NanaZip is bundled in another application or package, confirm the bundled version is updated.
- Use the vendor advisory and NVD record to validate that deployed builds are outside the affected version range.
Evidence notes
The supplied NVD metadata marks the CVE as analyzed and lists vulnerable versions from 5.0.1252.0 through before 6.0.1698.0. The record cites the vendor advisory as a mitigation reference, identifies CWE-369, and provides the CVSS 3.1 vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L, consistent with a local crash caused by divide-by-zero during image parsing.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42443 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42443
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42443 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42443
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/M2Team/NanaZip/security/advisories/GHSA-3x2h-gqqw-g3gm
[email protected] - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.