Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian 11 p7zip-rar DLA-4577-1 Memory Corruption DoS Risk CVE-2025-53816

debian lts
Calendar Grey May 11, 2026
Dist Debian Esm H88
Explore the Debian LTS advisory for p7zip-rar addressing a memory corruption issue that could lead to denial of service.
Jaroslav Lobačevski from GitHub Security Lab discovered a memory corruption vulnerability in the RAR module of p7zip, a now unmaintained fork of 7-Zip, a file archiver handling mu...

Summary

To address this vulnerability, whose fix is unfortunately not
isolated, and to remain compatible with the new p7zip package
(DLA-4576-1), this update replaces the p7zip code base with 7-Zip v25
(which now supports GNU/Linux natively), slightly modified to make it
reasonably compatible with p7zip.

For Debian 11 bullseye, this problem has been fixed in version
16.02+really25.00+ds-0+deb11u1.

We recommend that you upgrade your p7zip-rar packages.

For the detailed security status of p7zip-rar please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/p7zip-rar

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: p7zip-rar
Version: 16.02+really25.00+ds-0+deb11u1
CVE ID: CVE-2025-53816
Debian Bug: 1109494

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here