-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4718-1 [email protected]
https://www.debian.org/lts/security/ Sylvain Beucler
August 05, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : 7zip
Version : 22.01+really26.02+dfsg-0+deb12u1
CVE ID : CVE-2026-14266 CVE-2026-58052
Debian Bug : 1142293
Multiple vulnerabilities were discovered in 7-Zip, a file archiver
handling multiple formats.
Among the fixed vulnerabilities, the following were made public:
CVE-2026-14266
XZ decompression heap-based buffer overflow, potentially leading
to remote code execution.
CVE-2026-58052
RAR5 alternate-stream handling issue, when running on an NTFS
filesystem with transparent ADS (Alternate Data Stream) and ADS
canonicalization, letting an attacker defeat Mark-of-the-Web
warnings and spoof file content.
For Debian 12 bookworm, these problems have been fixed in version
22.01+really26.02+dfsg-0+deb12u1.
We recommend that you upgrade your 7zip packages.
For the detailed security status of 7zip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/7zip
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmpzaYYACgkQDTl9HeUl
XjBUdA//fRRQlHaIIKnaDDoxK36NZGjHdcJkDNejybUhwhfDZSw6IausF8yGuRiy
WJBZ7VBNa+yhagq5/P9ynZEWKb9mjjYErBXuRYdkzFhPhLb4SDGgVMgXnVPn9ajW
FdkcfMwdCJ8diOysS8R6FejWdCxadgBCe0PCd8uZHcErABoPy1pRVk31owf7pgi6
h2r3CNqCdfomDVxIg0iXNXnEnMoC7nqy2a8aM7bvlXVWwjgtfw8bwUfc99Ba0+lz
PqT3oxPm/+0NOawbHn5pRXILEJNDtzWtXXYF/PsViWjK5QRO1DUz3nnx/kJemnyt
xA53idqz+Mrk+Tzy5v0Gu5Yp02II67sHYCW0XQxqArq8fdyDWaUX58MrwtPDT3az
FX/a9ZBfsNWVn/4QKtXKeg1mQHehNNanOwXaQyh8+C4mOgcDuiNL3JhlUzFQIwUG
+Fg5eYnzvYDUn2pCnsF2vxMj7ULWkI2VQLJMyR96PDvAFYRZz5ovm+i9i9o/wsXB
IeRvZuNaDodri3Ks4bkgLUo/I33Rs7QlWuECdu+c7dx4PWpqQ5VjlKn9UmPbgdqD
GKApjUdunDBkJluOUN3XiX8cJyTy8VX4YBbOMdD3g7lbFnY9q7FiUDM1EIg6tW28
69xEpdtnmp2UPzV7HWvh39nAHOhOv3YBuDtmnBcKs1ijV4V4P1g=
=2QMV
-----END PGP SIGNATURE-----