-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4681-1 [email protected]
https://www.debian.org/lts/security/ Sylvain Beucler
July 13, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : p7zip
Version : 16.02+really26.01+dfsg-0+deb11u1
CVE ID : CVE-2026-48092 CVE-2026-48095 CVE-2026-48101 CVE-2026-48102
CVE-2026-48103 CVE-2026-48104 CVE-2026-48111 CVE-2026-48112
Multiple memory corruption vulnerabilities were discovered in p7zip, a
now unmaintained fork of 7-Zip, which itself is a file archiver
handling multiple formats.
To address these security vulnerabilities, whose fixes are
unfortunately not isolated, this update again replaces p7zip with a
recent 7-Zip (now v26.01), slightly modified to make it reasonably
compatible with p7zip.
CVE-2026-48092
SquashFS Fragment Offset Overflow
CVE-2026-48095
Heap Buffer Write Overflow
CVE-2026-48101
UEFI Capsule uninitialized heap memory disclosure
CVE-2026-48102
UDF Field OOB Read
CVE-2026-48103
WIM SecurityId OOB read
CVE-2026-48104
SquashFS BlockToNode uninitialized heap read
CVE-2026-48111
UEFI DEPEX OOB Read
CVE-2026-48112
Ar SYMDEF OOB Read
For Debian 11 bullseye, these problems have been fixed in version
16.02+really26.01+dfsg-0+deb11u1.
We recommend that you upgrade your p7zip packages.
For the detailed security status of p7zip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/p7zip
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmpVPBQACgkQDTl9HeUl
XjDdtRAAogdPx1ZIftuPB8w5KbEsxzbnCVGezSkpZFLWqIubJ7tWBQy/LZOSHm6v
B6hhonbISH2W72VyHolp51codPpWK6BclfFVrknmS5x4ylr3wRsvTdDQ+HM0JiLv
1NgT5QBEyFoosyNErJR5qR/Xy0GJokeBU37kIs0y4D5i1lPQ9999A/8K2T3R1OJG
XqhvznUPccZo7yP6GwaxpxWkNBo4mAgccDpPBaWyvwlunLhl/c6TvuEnLRi6U89a
m4HZkn8/uCdmOezMqt0VRZNWJxqEUxIvGEx9/jH8GPV0cyTM2PuTZmPPG+saFuho
bAueW6cKxJywiSETwkRjq5AzmY3fzqPERccqN0dGrX3Gi0NbDAcJPXRlfLygDhf+
FNVJQjI85w7A3OdPckTKIKRXJR7mbO7Irj2w4NZRZt6R8lQknEitKJquO7rWTsqA
nDe8E/XIIDVvlKRQd8Y3qB5hrmcO/mklkkmSQQVPCKP29G5pIwKu+w/c+HF9K9mP
yhu5lIfcgiHm1HAwwApRug6r1CMiQrbAb8ttd3NMHRtoT1+AENvbO76DfKGB/1/h
RJDmWe99D/Ont4SxUKzAP14IUDVcs5YsS1AoRzomlefa+W6zPek66nLLsG8qBVp9
LXn4ZBF2P13CBTgABfB5T7uVkkRtMB34O0vRux/EPFCnDX3uoQM=
=Yz5S
-----END PGP SIGNATURE-----