Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Unbounded Memory Allocation DoS in NanaZip 6.5 (CVE‑2026‑55781) Disrupts Archive Processing

A crafted UFS image triggers an unbounded memory allocation in NanaZip 6.5, causing a denial‑of‑service on Windows. The flaw (CVE‑2026‑55781) is fixed in version 6.5.1749.0 and highlights the need for continuous vulnerability management in SOC 2 programs.

LiveThreat™ Intelligence · 📅 August 19, 2026· 📰 exploit-db.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
exploit-db.com

Critical Unbounded Memory Allocation DoS in NanaZip 6.5 (CVE‑2026‑55781) Disrupts Archive Processing

What Happened – A crafted UFS image can set the fs_bsize field to 1 GiB, triggering an unbounded memory allocation in the NanaZip 6.5 UFS handler. The parser allocates up to ~3 GiB before any bounds check, causing a denial‑of‑service on Windows hosts. The issue is fixed in version 6.5.1749.0.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates why SOC 2 Control CC6.1 (Risk Mitigation) and CC7.1 (Vulnerability Management) must include continuous scanning of third‑party libraries.
  • Provides concrete evidence for audit trails: patch‑management logs, vulnerability‑remediation tickets, and proof of control effectiveness.
  • Aligns with Verisq’s Control Mapping capability, which continuously maps discovered flaws to SOC 2 controls and supplies real‑time evidence for auditors.

Who Is Affected – Software vendors, SaaS platforms, and any organization that integrates NanaZip for compression or archival tasks (tech‑SaaS, development tools, internal IT utilities).

Recommended Actions

  • Upgrade all NanaZip installations to 6.5.1749.0 or later.
  • Add the UFS parser to your vulnerability‑scanning rule set and verify remediation in your CMDB.
  • Map the CVE to SOC 2 CC6.1/CC7.1 controls, capture patch‑deployment evidence, and retain logs for audit review.

Technical Notes – The exploit manipulates the fs_bsize field in a UFS2 superblock (offset 0x30) to 0x40000000, bypassing the lower‑bound check and forcing three 1 GiB indirect buffers. No remote code execution is achieved; impact is limited to memory exhaustion and service crash. Source: Exploit‑DB 52656

📰 Original Source
https://www.exploit-db.com/exploits/52656 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →