ELA-1742-1 p7zip security update

multiple vulnerabilities

2026-06-01
Packagep7zip
Version16.02+really25.01+dfsg-0+deb9u1 (stretch), 16.02+really25.01+dfsg-0+deb10u1 (buster)
Related CVEs CVE-2022-47069 CVE-2023-31102 CVE-2023-40481 CVE-2023-52168 CVE-2023-52169 CVE-2024-11612 CVE-2025-11001 CVE-2025-11002 CVE-2025-53817 CVE-2025-55188


Multiple vulnerabilities were discovered in p7zip, a now unmaintained fork of 7-Zip, a file archiver handling multiple formats.

To address these security vulnerabilities, whose fixes are unfortunately not isolated, this update replaces p7zip with 7-Zip v25 (which now supports GNU/Linux natively), slightly modified to make it reasonably compatible with p7zip.



For Debian 10 buster, these problems have been fixed in version 16.02+really25.01+dfsg-0+deb10u1.

For Debian 9 stretch, these problems have been fixed in version 16.02+really25.01+dfsg-0+deb9u1.

We recommend that you upgrade your p7zip packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.