NanaZip 6.0 Update 6 (6.0.1701.0)
- Synchronize 7-Zip mainline implementations to 26.01 except the NanaZip File Manager
- Fixed security vulnerabilities GHSL-2026-116 through GHSL-2026-122 synchronized from 7-Zip 26.01
- Fixed security vulnerability GHSL-2026-124 (CVE-2026-54616)
- Fixed security vulnerability GHSL-2026-125 (CVE-2026-44215)
- Fixed security vulnerability GHSL-2026-126 (CVE-2026-47222)
- Fixed security vulnerability GHSL-2026-127 (CVE-2026-47223)
- Fixed security vulnerability GHSL-2026-128 (CVE-2026-42446)
- Fixed security vulnerability GHSL-2026-129 (CVE-2026-47224)
- Fixed security vulnerability GHSL-2026-130 (CVE-2026-42442)
- Fixed security vulnerability GHSL-2026-131 (CVE-2026-42443)
- Fixed security vulnerability GHSL-2026-132 (CVE-2026-42445)
- Fixed security vulnerability GHSL-2026-133 (CVE-2026-42355)
- Fixed security vulnerability GHSL-2026-134 (CVE-2026-42444)
- Fixed security vulnerability GHSL-2026-140 (CVE-2026-48095) synchronized from 7-Zip 26.01
I'm excited to announce that we've released the NanaZip 6.0 Update 6, now available for download.
Note: The next 6.5 Preview has been delayed to May or June because my boss asked me to wrestle with the ugly media player implementation before June, and I'll need a little time afterward to recover what’s left of my sanity.
Starting with NanaZip 6.0 Update 5 (6.0.1698.0), we have fixed some security vulnerabilities reported by JarLob (Jaroslav Lobačevski):
Note: It seems the CVE numbers are not available, use the GHSL number instead.
Note: The current NanaZip 6.5 Preview has not fixed these issues. Please wait for the next 6.5 Preview.
- GHSL-2026-116–GHSL-2026-122 (CVE-2026-48092, CVE-2026-48101, CVE-2026-48102, CVE-2026-48103, CVE-2026-48104, CVE-2026-48111, CVE-2026-48112), synchronized from 7-Zip 26.01
- GHSL-2026-124, CVE-2026-54616
- GHSL-2026-125, CVE-2026-44215
- GHSL-2026-126, CVE-2026-47222
- GHSL-2026-127, CVE-2026-47223
- GHSL-2026-128, CVE-2026-42446
- GHSL-2026-129, CVE-2026-47224
- GHSL-2026-130, CVE-2026-42442
- GHSL-2026-131, CVE-2026-42443
- GHSL-2026-132, CVE-2026-42445
- GHSL-2026-133, CVE-2026-42355
- GHSL-2026-134, CVE-2026-42444
- GHSL-2026-140, CVE-2026-48095, synchronized from 7-Zip 26.01
Note to developers: GHSL-2026-126, GHSL-2026-127 and GHSL-2026-129 originated from an issue existing in parts of 7-Zip source code which were specifically enabled in NanaZip (LvmHandler.cpp and AvbHandler.cpp). If you forked 7-Zip to enable these handlers, you should synchronize with 7-Zip 26.01 for the fix. NanaZip is not vulnerable to GHSL-2026-115 due to that vulnerability being limited to the 7-Zip SDK.
Release Notes
- Synchronize 7-Zip mainline implementations to 26.01. (Except the NanaZip File Manager.) (Thanks to Igor Pavlov.)
Download
-
MSIX Package: NanaZip_6.0.1701.0.msixbundle
- SHA-256: 83e61e3bf8359f3aed5dba3487eae7c620b3ace48fc5d168af8b89221f067e78
-
License XML: NanaZip_6.0.1701.0.xml
- SHA-256: 2269c29cda8a64a37ad97a56d53da59d479e30e5f14265b45769f21f05e997d8
-
Portable package: NanaZip_6.0.1701.0_Binaries.zip
- SHA-256: 995448ef4a28dc37e943f127ac971e3e5ea990a432a2589dc5215188c3392d4c
-
Debug Symbols: NanaZip_6.0.1701.0_DebugSymbols.zip
- SHA-256: 6c4e633e2bdfb2259532fe3c8bb712220c0fc54036c703f80fc984b633146bcf
Kenji Mouri