Re: [BLFS Trac] #23508: 7zip-26.02

BLFS Trac ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23508: 7zip-26.02
-------------------------+-------------------------------
 Reporter:  Bruce Dubbs  |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  elevated     |   Milestone:  98-Security
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Comment (by Joe Locash):

 {{{
 Message-ID: <[email protected]>
 Date: Fri, 17 Jul 2026 13:00:21 -0700
 From: Alan Coopersmith <[email protected]>
 To: [email protected]
 Subject: 7-Zip XZ Decompression Heap-based Buffer Overflow
  Remote Code Execution Vulnerability

 https://www.zerodayinitiative.com/advisories/ZDI-26-444/ advises:
 > 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution
 > Vulnerability
 >
 > July 15th, 2026
 > ZDI-26-444 ZDI-CAN-30169
 >
 > CVE ID
 > CVE-2026-14266
 >
 > CVSS Score
 > 7.0 AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
 >
 > Affected Vendors
 > 7-Zip
 >
 > Affected Products
 > 7-Zip
 >
 > Vulnerability Details
 >
 > This vulnerability allows remote attackers to execute arbitrary code on
 > affected installations of 7-Zip. User interaction is required to exploit
 > this vulnerability in that the target must visit a malicious page or
 open
 > a malicious file.
 >
 > The specific flaw exists within the processing of XZ chunked data.
 > Crafted XZ-compressed data can trigger an overflow of a heap-based
 buffer.
 > An attacker can leverage this vulnerability to execute code in the
 context
 > of the current process.
 >
 > Additional Details
 >
 > Fixed in 7-Zip 26.02
 >
 > Disclosure Timeline
 >
 >     2026-06-05 - Vulnerability reported to vendor
 >     2026-07-15 - Coordinated public release of advisory
 >     2026-07-15 - Advisory Updated
 >
 > Credit
 >
 > Lunbun LLC (Landon Peng)
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23508#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.