{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "details",
        "text": "With respect to Directive (EU) 2019/770 and Directive (EU) 2019/771 and their national transposition laws, please note:\n\nIt is your responsibility to download and/or install any security updates provided by us, for example to maintain product or data security. If you fail to install a security update provided to you within a reasonable period of time, we will not be liable for any product defect solely due to the absence of such security update.\n\nAlternatively, we are entitled to directly download and/or install security updates regardless of your settings. In these cases, we will provide you with the relevant information, e.g. in this security advisory.",
        "title": "Security Update Information"
      },
      {
        "category": "details",
        "text": "\nVulnerability classification has been performed using the CVSS v3.1 scoring system. The CVSS environmental score is specific to each customer's environment and should be defined by the customer to attain a final scoring.",
        "title": "CVSS Scoring"
      },
      {
        "category": "description",
        "text": "Bosch Rexroth AG PRI7000",
        "title": "Product description for Bosch Rexroth AG PRI7000"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@bosch.com",
      "issuing_authority": "Robert Bosch GmbH",
      "name": "Bosch PSIRT",
      "namespace": "https://psirt.bosch.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "Researcher advisory",
        "url": "https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip"
      },
      {
        "category": "self",
        "summary": "PRI7000 product page",
        "url": "https://store.boschrexroth.com/de/de/pri7000-engineering-software"
      },
      {
        "category": "self",
        "summary": "Bosch Rexroth Advisory",
        "url": "https://www.boschrexroth.com/de/de/search.html?q=ALL&s=download&dnavs=+DC_mediatype%3Adc_media_type_security_advisory&orderby=mes%3Adate&order_direction=DESCENDING&origin=direct&num=100"
      }
    ],
    "title": "Heap Overflow in PRI7000",
    "tracking": {
      "current_release_date": "2026-07-22T07:12:00.000Z",
      "generator": {
        "date": "2026-07-22T07:16:31.865Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.6"
        }
      },
      "id": "BOSCH-SA-466086",
      "initial_release_date": "2026-07-22T07:12:00.000Z",
      "revision_history": [
        {
          "date": "2026-07-22T07:12:00.000Z",
          "number": "1",
          "summary": "Initial Revision"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.11.18.2",
                "product": {
                  "name": "Bosch Rexroth AG PRI7000 1.11.18.2",
                  "product_id": "cb497a663f3",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:boschrexroth:pri7000:1.11.18.2:*:*:*:*:*:*:*"
                  }
                }
              },
              {
                "category": "product_version_range",
                "name": "<=1.11.18.1",
                "product": {
                  "name": "Bosch Rexroth AG PRI7000 all <= 1.11.18.1",
                  "product_id": "74490dd703c",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:boschrexroth:pri7000:*:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "Bosch Rexroth AG PRI7000"
          }
        ],
        "category": "vendor",
        "name": "Bosch"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-48095",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)1 << (BlockSizeLog + CompressionUnit), and a crafted image with ClusterSizeLog >= 28 and CompressionUnit == 4 drives the exponent to 32, which is undefined behavior and collapses on x86/x64 so _inBuf is allocated as 1 byte. ReadStream_FALSE then writes up to 256 MB of attacker-controlled data into that 1-byte buffer in 64 KB iterations, and because the CInStream object sits only 304 bytes after _inBuf, its vtable pointer is overwritten and the next dispatched call achieves a vtable hijack. On 32-bit builds the overflow is unconditionally reached; on 64-bit it requires the parallel 8 GB _outBuf allocation to succeed, otherwise failing closed to denial of service. The NTFS handler is enabled by default in stock 7z.dll and, via signature-based fallback matching \"NTFS    \" at offset 3, will open a crafted image regardless of file extension during extraction or testing. Version 26.01 fixes the issue.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "cb497a663f3"
        ],
        "known_affected": [
          "74490dd703c"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update to PRI7000 version 1.11.18.2 or newer, if possible.",
          "product_ids": [
            "74490dd703c"
          ]
        },
        {
          "category": "mitigation",
          "details": "Navigate to the \"Simulator\" Folder typically installed on drive (C:)Windows - ProgramData - Bosch Rexroth AG - PRI7000_Data - V.1.11.XX.X - Common - Simulator\nIn the Simulator folder you can choose three different releases of the PRI7000. The actual one and the two versions before.\nFor each Version please navigate into the \"7zip\" folder V1.11.XX.X - App - Tools - 7zip\nPlease delete the Folder \"Far\" in each of the three versions\nThe vulnerable source code is deleted from the computer and can not affect the installed PRI7000 versions",
          "product_ids": [
            "74490dd703c"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "74490dd703c"
          ]
        }
      ],
      "title": "GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation"
    }
  ]
}