-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4719-1                [email protected]
https://www.debian.org/lts/security/                      Sylvain Beucler
August 05, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : p7zip
Version        : 16.02+really26.02+dfsg-0+deb11u1
                 16.02+really26.02+dfsg-0+deb12u1
CVE ID         : CVE-2026-14266 CVE-2026-58052
Debian Bug     : 1142293

Multiple vulnerabilities were discovered in p7zip, a now unmaintained
fork of 7-Zip, which itself is a file archiver handling multiple
formats.

To address these security vulnerabilities, whose fixes unfortunately
cannot be isolated, this update again replaces p7zip with a recent
7-Zip (now v26.02), slightly modified to make it reasonably compatible
with p7zip.

Among the fixed vulnerabilities, the following were made public:

CVE-2026-14266

    XZ decompression heap-based buffer overflow, potentially leading
    to remote code execution.

CVE-2026-58052

    RAR5 alternate-stream handling issue, when running on an NTFS
    filesystem with transparent ADS (Alternate Data Stream) and ADS
    canonicalization, letting an attacker defeat Mark-of-the-Web
    warnings and spoof file content.

For Debian 11 bullseye, these problems have been fixed in version
16.02+really26.02+dfsg-0+deb11u1.

For Debian 12 bookworm, these problems have been fixed in version
16.02+really26.02+dfsg-0+deb12u1.

We recommend that you upgrade your p7zip packages.

For the detailed security status of p7zip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/p7zip

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmpzaaMACgkQDTl9HeUl
XjDSqxAAqHI9FLEJdSLbehAVQ03W3ERWSEo1arckXbDMFhCn7fPpU6pCx740/oRg
1gwbmF7snBpfwQvv9c7uHdYkv1F7bE0ERAQP+fUTdHR7Sy0FeLCAChtX+5jpmdRR
1F8aZcHZL5bGltVGeZJnW+uF3v8zhQmDgVR+IQm0JE3cvwLt4xVvyNI4VruYOklm
qiEOvtXNbXV9Z81xt1kisBcltHXXHWbpI/14WNfICOQH0qgXzP09frc9b3LYZJOb
zktXs7gVlTRWInTEirZ/flABktIKg4slSpcZNCKVkfti0+C4bkWh9+uT/p0dzBxB
dRUHHlbkYM3/dpnp3Km+N4yyK0WCyeIxG/LrpTUjzQuT5KXymamD/0hbu1CeoywK
cmEONv2A6r7Op/CVAEstDMPYBDLOpnu/d4yURYUNMezUsmEPeqZjwzEOMJt4rJ48
G/i48ebBsQLYD5sBg/wTn60AUYDAnJAkL6aSDwuf5ArxPnxyH9v8z570MkpoSNnZ
ACKnAmQrAVNRu9JhFwPhuAPHJK2jBWGE2F7EAidP38fe/za820RZKA6EzuvidrSY
Kv2XHvnrYKAa/hA84zniyvRE5DAfju1MTDloQnJ1fUAVxVZJN9Dwue609OXZP2T/
9w3y9btInGcR3ELreV1Qstwfm7TsPDCQmgwLIXGStn2HGxM0fdg=
=gNPR
-----END PGP SIGNATURE-----

Reply via email to