-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4719-1 [email protected]
https://www.debian.org/lts/security/ Sylvain Beucler
August 05, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : p7zip
Version : 16.02+really26.02+dfsg-0+deb11u1
16.02+really26.02+dfsg-0+deb12u1
CVE ID : CVE-2026-14266 CVE-2026-58052
Debian Bug : 1142293
Multiple vulnerabilities were discovered in p7zip, a now unmaintained
fork of 7-Zip, which itself is a file archiver handling multiple
formats.
To address these security vulnerabilities, whose fixes unfortunately
cannot be isolated, this update again replaces p7zip with a recent
7-Zip (now v26.02), slightly modified to make it reasonably compatible
with p7zip.
Among the fixed vulnerabilities, the following were made public:
CVE-2026-14266
XZ decompression heap-based buffer overflow, potentially leading
to remote code execution.
CVE-2026-58052
RAR5 alternate-stream handling issue, when running on an NTFS
filesystem with transparent ADS (Alternate Data Stream) and ADS
canonicalization, letting an attacker defeat Mark-of-the-Web
warnings and spoof file content.
For Debian 11 bullseye, these problems have been fixed in version
16.02+really26.02+dfsg-0+deb11u1.
For Debian 12 bookworm, these problems have been fixed in version
16.02+really26.02+dfsg-0+deb12u1.
We recommend that you upgrade your p7zip packages.
For the detailed security status of p7zip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/p7zip
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmpzaaMACgkQDTl9HeUl
XjDSqxAAqHI9FLEJdSLbehAVQ03W3ERWSEo1arckXbDMFhCn7fPpU6pCx740/oRg
1gwbmF7snBpfwQvv9c7uHdYkv1F7bE0ERAQP+fUTdHR7Sy0FeLCAChtX+5jpmdRR
1F8aZcHZL5bGltVGeZJnW+uF3v8zhQmDgVR+IQm0JE3cvwLt4xVvyNI4VruYOklm
qiEOvtXNbXV9Z81xt1kisBcltHXXHWbpI/14WNfICOQH0qgXzP09frc9b3LYZJOb
zktXs7gVlTRWInTEirZ/flABktIKg4slSpcZNCKVkfti0+C4bkWh9+uT/p0dzBxB
dRUHHlbkYM3/dpnp3Km+N4yyK0WCyeIxG/LrpTUjzQuT5KXymamD/0hbu1CeoywK
cmEONv2A6r7Op/CVAEstDMPYBDLOpnu/d4yURYUNMezUsmEPeqZjwzEOMJt4rJ48
G/i48ebBsQLYD5sBg/wTn60AUYDAnJAkL6aSDwuf5ArxPnxyH9v8z570MkpoSNnZ
ACKnAmQrAVNRu9JhFwPhuAPHJK2jBWGE2F7EAidP38fe/za820RZKA6EzuvidrSY
Kv2XHvnrYKAa/hA84zniyvRE5DAfju1MTDloQnJ1fUAVxVZJN9Dwue609OXZP2T/
9w3y9btInGcR3ELreV1Qstwfm7TsPDCQmgwLIXGStn2HGxM0fdg=
=gNPR
-----END PGP SIGNATURE-----