Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 606
Alerts This Week
Warning Icon 1 606

openSUSE 7zip Important Security Update for 8 Issues 2026-2696-1

opensuse
Calendar Grey June 30, 2026
Scroller Opensuse
# Security update for 7zip Announcement ID: SUSE-SU-2026:2696-1 Release Date: 2026-06-30T09:10:05Z R
An update that solves eight vulnerabilities can now be installed.

Description

This update for 7zip fixes the following issues

Update to 26.01:

* CVE-2026-48092: Information disclosure in 32-bit builds due to heap memory

disclosure (bsc#1267858).

* CVE-2026-48095: Heap buffer overflow via NTFS compressed stream buffer

under-allocation (bsc#1267421).

* CVE-2026-48101: Information Disclosure via uninitialized memory in UEFI

capsule parser (bsc#1267859).

* CVE-2026-48102: Information disclosure and denial of service via crafted UDF

image (bsc#1267860).

* CVE-2026-48103: off-by-one heap out-of-bounds read (bsc#1267861).

* CVE-2026-48104: Uninitialized heap read in SquashFS archive handler

(bsc#1267862).

* CVE-2026-48111: off-by-one out-of-bounds read in ParseDepedencyExpression

function (bsc#1267863).

* CVE-2026-48112: heap out-of-bounds read in BSD SYMDEF parser (bsc#1267864).

Changes:

* linux version of 7-Zip can use huge pages (2 MB pages). It can increase

compression speed for 10% for 7z/xz/LZMA/LZMA2...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2696=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2696=1

* Basesystem Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2696=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2696=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2696=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2696=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5

zypper in -t patch...

Read the Full Advisory

Package List

* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)

* 7zip-26.01-150400.9.6.1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64

x86_64)

* 7zip-26.01-150400.9.6.1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64

x86_64)

* 7zip-26.01-150400.9.6.1

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)

* 7zip-26.01-150400.9.6.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)

* 7zip-26.01-150400.9.6.1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64

x86_64)

* 7zip-26.01-150400.9.6.1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64

x86_64)

* 7zip-26.01-150400.9.6.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)

* 7zip-26.01-150400.9.6.1

* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)

* 7zip-26.01-150400.9.6.1

* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)

* 7zip-26.01-150400.9.6.1

* SUSE Linux Enterprise...

Read the Full Advisory

References

* bsc#1267421

* bsc#1267858

* bsc#1267859

* bsc#1267860

* bsc#1267861

* bsc#1267862

* bsc#1267863

* bsc#1267864

## References:

* https://www.suse.com/security/cve/CVE-2026-48092.html

* https://www.suse.com/security/cve/CVE-2026-48095.html

* https://www.suse.com/security/cve/CVE-2026-48101.html

* https://www.suse.com/security/cve/CVE-2026-48102.html

* https://www.suse.com/security/cve/CVE-2026-48103.html

* https://www.suse.com/security/cve/CVE-2026-48104.html

* https://www.suse.com/security/cve/CVE-2026-48111.html

* https://www.suse.com/security/cve/CVE-2026-48112.html

* https://bugzilla.suse.com/show_bug.cgi?id=1267421

* https://bugzilla.suse.com/show_bug.cgi?id=1267858

* https://bugzilla.suse.com/show_bug.cgi?id=1267859

* https://bugzilla.suse.com/show_bug.cgi?id=1267860

* https://bugzilla.suse.com/show_bug.cgi?id=1267861

* https://bugzilla.suse.com/show_bug.cgi?id=1267862

* https://bugzilla.suse.com/show_bug.cgi?id=1267863

* https://bugzilla.suse.com/show_bug.cgi?id=1267864

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2696-1
Release Date: 2026-06-30T09:10:05Z
Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.