| Package | p7zip |
|---|---|
| Version | 16.02+really26.02+dfsg-0+deb9u1 (stretch), 16.02+really26.02+dfsg-0+deb10u1 (buster) |
| Related CVEs | CVE-2026-14266 CVE-2026-48092 CVE-2026-48095 CVE-2026-48101 CVE-2026-48102 CVE-2026-48103 CVE-2026-48104 CVE-2026-48111 CVE-2026-48112 CVE-2026-58052 |
Multiple vulnerabilities were discovered in p7zip, a now unmaintained fork of 7-Zip, which itself is a file archiver handling multiple formats.
To address these security vulnerabilities, whose fixes unfortunately cannot be isolated, this update again replaces p7zip with a recent 7-Zip (now v26.02), slightly modified to make it reasonably compatible with p7zip.
Among the fixed vulnerabilities, the following were made public:
-
CVE-2026-14266
XZ decompression heap-based buffer overflow, potentially leading to remote code execution.
-
CVE-2026-48092
SquashFS Fragment Offset Overflow
-
CVE-2026-48095
Heap Buffer Write Overflow
-
CVE-2026-48101
UEFI Capsule uninitialized heap memory disclosure
-
CVE-2026-48102
UDF Field OOB Read
-
CVE-2026-48103
WIM SecurityId OOB read
-
CVE-2026-48104
SquashFS BlockToNode uninitialized heap read
-
CVE-2026-48111
UEFI DEPEX OOB Read
-
CVE-2026-48112
Ar SYMDEF OOB Read
-
CVE-2026-58052
RAR5 alternate-stream handling issue, when running on an NTFS filesystem with transparent ADS (Alternate Data Stream) and ADS canonicalization, letting an attacker defeat Mark-of-the-Web warnings and spoof file content.
For Debian 10 buster, these problems have been fixed in version 16.02+really26.02+dfsg-0+deb10u1.
For Debian 9 stretch, these problems have been fixed in version 16.02+really26.02+dfsg-0+deb9u1.
We recommend that you upgrade your p7zip packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.