-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4681-1                [email protected]
https://www.debian.org/lts/security/                      Sylvain Beucler
July 13, 2026                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : p7zip
Version        : 16.02+really26.01+dfsg-0+deb11u1
CVE ID         : CVE-2026-48092 CVE-2026-48095 CVE-2026-48101 CVE-2026-48102 
                 CVE-2026-48103 CVE-2026-48104 CVE-2026-48111 CVE-2026-48112

Multiple memory corruption vulnerabilities were discovered in p7zip, a
now unmaintained fork of 7-Zip, which itself is a file archiver
handling multiple formats.

To address these security vulnerabilities, whose fixes are
unfortunately not isolated, this update again replaces p7zip with a
recent 7-Zip (now v26.01), slightly modified to make it reasonably
compatible with p7zip.

CVE-2026-48092

    SquashFS Fragment Offset Overflow

CVE-2026-48095

    Heap Buffer Write Overflow

CVE-2026-48101

    UEFI Capsule uninitialized heap memory disclosure

CVE-2026-48102

    UDF Field OOB Read

CVE-2026-48103

    WIM SecurityId OOB read

CVE-2026-48104

    SquashFS BlockToNode uninitialized heap read

CVE-2026-48111

    UEFI DEPEX OOB Read

CVE-2026-48112

    Ar SYMDEF OOB Read

For Debian 11 bullseye, these problems have been fixed in version
16.02+really26.01+dfsg-0+deb11u1.

We recommend that you upgrade your p7zip packages.

For the detailed security status of p7zip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/p7zip

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmpVPBQACgkQDTl9HeUl
XjDdtRAAogdPx1ZIftuPB8w5KbEsxzbnCVGezSkpZFLWqIubJ7tWBQy/LZOSHm6v
B6hhonbISH2W72VyHolp51codPpWK6BclfFVrknmS5x4ylr3wRsvTdDQ+HM0JiLv
1NgT5QBEyFoosyNErJR5qR/Xy0GJokeBU37kIs0y4D5i1lPQ9999A/8K2T3R1OJG
XqhvznUPccZo7yP6GwaxpxWkNBo4mAgccDpPBaWyvwlunLhl/c6TvuEnLRi6U89a
m4HZkn8/uCdmOezMqt0VRZNWJxqEUxIvGEx9/jH8GPV0cyTM2PuTZmPPG+saFuho
bAueW6cKxJywiSETwkRjq5AzmY3fzqPERccqN0dGrX3Gi0NbDAcJPXRlfLygDhf+
FNVJQjI85w7A3OdPckTKIKRXJR7mbO7Irj2w4NZRZt6R8lQknEitKJquO7rWTsqA
nDe8E/XIIDVvlKRQd8Y3qB5hrmcO/mklkkmSQQVPCKP29G5pIwKu+w/c+HF9K9mP
yhu5lIfcgiHm1HAwwApRug6r1CMiQrbAb8ttd3NMHRtoT1+AENvbO76DfKGB/1/h
RJDmWe99D/Ont4SxUKzAP14IUDVcs5YsS1AoRzomlefa+W6zPek66nLLsG8qBVp9
LXn4ZBF2P13CBTgABfB5T7uVkkRtMB34O0vRux/EPFCnDX3uoQM=
=Yz5S
-----END PGP SIGNATURE-----

Reply via email to