Re: [BLFS Trac] #23508: 7zip-26.02
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23508: 7zip-26.02
-------------------------+-------------------------------
Reporter: Bruce Dubbs | Owner: SecurityAdvisory
Type: enhancement | Status: new
Priority: elevated | Milestone: 98-Security
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-------------------------------
Comment (by Joe Locash):
{{{
Message-ID: <[email protected]>
Date: Fri, 17 Jul 2026 13:00:21 -0700
From: Alan Coopersmith <[email protected]>
To: [email protected]
Subject: 7-Zip XZ Decompression Heap-based Buffer Overflow
Remote Code Execution Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-26-444/ advises:
> 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution
> Vulnerability
>
> July 15th, 2026
> ZDI-26-444 ZDI-CAN-30169
>
> CVE ID
> CVE-2026-14266
>
> CVSS Score
> 7.0 AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
>
> Affected Vendors
> 7-Zip
>
> Affected Products
> 7-Zip
>
> Vulnerability Details
>
> This vulnerability allows remote attackers to execute arbitrary code on
> affected installations of 7-Zip. User interaction is required to exploit
> this vulnerability in that the target must visit a malicious page or
open
> a malicious file.
>
> The specific flaw exists within the processing of XZ chunked data.
> Crafted XZ-compressed data can trigger an overflow of a heap-based
buffer.
> An attacker can leverage this vulnerability to execute code in the
context
> of the current process.
>
> Additional Details
>
> Fixed in 7-Zip 26.02
>
> Disclosure Timeline
>
> 2026-06-05 - Vulnerability reported to vendor
> 2026-07-15 - Coordinated public release of advisory
> 2026-07-15 - Advisory Updated
>
> Credit
>
> Lunbun LLC (Landon Peng)
}}}
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23508#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page