Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security update. Publication date: 09 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0238.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-48095 Description: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation. (CVE-2026-48095) References: - https://bugs.mageia.org/show_bug.cgi?id=35647 - https://lists.opensuse.org/archives/list/
7-zip 26.02 Some bugs and vulnerabilities were fixed.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-7eaa63bea6 2026-07-04 01:06:18.979289+00:00 -------------------------------------------------------------------------------- Name : 7zip Product : Fedora 43 Version : 26.02 Release : 1.fc43 URL : https://7-zip.org Summary : A file archiver Description : 7-Zip is a file archiver with a high compression ratio. The main features of 7-Zip are: * High compression ratio in 7z format with LZMA and LZMA2 compression * Supported formats: * Packing / unpacking: 7z, XZ, BZIP2, GZIP, TAR, ZIP and WIM * Unpacking only: AR, ARJ, CAB, CHM, CPIO, CramFS, DMG, EXT, FAT, GPT, HFS, IHEX, ISO, LZH, LZMA, MBR, MSI, NSIS, NTFS, QCOW2, RPM, SquashFS, UDF, UEFI, VDI, VHD, VMDK, WIM, XAR and Z. * For ZIP and GZIP formats, 7-Zip provides a compression ratio that is 2-10 % better than the ratio provided by PKZip and WinZip * Strong AES-256 encryption in 7z and ZIP formats * Powerful command line version -------------------------------------------------------------------------------- Update Information: 7-zip 26.02 Some bugs and vulnerabilities were fixed. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 1 2026 Michel Lind - 26.02-1 - Update to version 26.02; Resolves: rhbz#2493347 * Wed Jul 1 2026 Michel Lind - 26.01-2 - Load 7z.so from a fixed libexec path instead of deriving it from argv[0] - Resolves: rhbz#2491337 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2491337 - 7-zip under the root account cannot extract RAR archives https://bugzilla.redhat.com/show_bug.cgi?id=2491337 [ 2 ] Bug #2493347 - 7zip-26.02 is available https://bugzilla.redhat.com/show_bug.cgi?id=2493347 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7eaa63bea6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
7-zip 26.02 Some bugs and vulnerabilities were fixed.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-948b74882b 2026-07-03 00:54:50.177281+00:00 -------------------------------------------------------------------------------- Name : 7zip Product : Fedora 44 Version : 26.02 Release : 1.fc44 URL : https://7-zip.org Summary : A file archiver Description : 7-Zip is a file archiver with a high compression ratio. The main features of 7-Zip are: * High compression ratio in 7z format with LZMA and LZMA2 compression * Supported formats: * Packing / unpacking: 7z, XZ, BZIP2, GZIP, TAR, ZIP and WIM * Unpacking only: AR, ARJ, CAB, CHM, CPIO, CramFS, DMG, EXT, FAT, GPT, HFS, IHEX, ISO, LZH, LZMA, MBR, MSI, NSIS, NTFS, QCOW2, RPM, SquashFS, UDF, UEFI, VDI, VHD, VMDK, WIM, XAR and Z. * For ZIP and GZIP formats, 7-Zip provides a compression ratio that is 2-10 % better than the ratio provided by PKZip and WinZip * Strong AES-256 encryption in 7z and ZIP formats * Powerful command line version -------------------------------------------------------------------------------- Update Information: 7-zip 26.02 Some bugs and vulnerabilities were fixed. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 1 2026 Michel Lind - 26.02-1 - Update to version 26.02; Resolves: rhbz#2493347 * Wed Jul 1 2026 Michel Lind - 26.01-2 - Load 7z.so from a fixed libexec path instead of deriving it from argv[0] - Resolves: rhbz#2491337 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2491337 - 7-zip under the root account cannot extract RAR archives https://bugzilla.redhat.com/show_bug.cgi?id=2491337 [ 2 ] Bug #2493347 - 7zip-26.02 is available https://bugzilla.redhat.com/show_bug.cgi?id=2493347 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-948b74882b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves eight vulnerabilities can now be installed.. # Security update for 7zip Announcement ID: SUSE-SU-2026:22347-1 Release Date: 2026-06-23T12:46:58Z Rating: important References: * bsc#1267421 * bsc#1267858 * bsc#1267859 * bsc#1267860 * bsc#1267861 * bsc#1267862 * bsc#1267863 * bsc#1267864 Cross-References: * CVE-2026-48092 * CVE-2026-48095 * CVE-2026-48101 * CVE-2026-48102 * CVE-2026-48103 * CVE-2026-48104 * CVE-2026-48111 * CVE-2026-48112 CVSS scores: * CVE-2026-48092 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48092 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48092 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-48095 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-48095 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-48101 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48101 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48102 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48102 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48102 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48102 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48103 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48103 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48103 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48103 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-48104 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48104 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-48104 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-48111 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48111 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48111 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48111 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-48112 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48112 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48112 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for 7zip fixes the following issues Update to 26.01: * CVE-2026-48092: Information disclosure in 32-bit builds due to heap memory disclosure (bsc#1267858). * CVE-2026-48095: Heap buffer overflow via NTFS compressed stream buffer under-allocation (bsc#1267421). * CVE-2026-48101: Information Disclosure via uninitialized memory in UEFI capsule parser (bsc#1267859). * CVE-2026-48102: Information disclosure and denial of service via crafted UDF image (bsc#1267860). * CVE-2026-48103: off-by-one heap out-of-bounds read (bsc#1267861). * CVE-2026-48104: Uninitialized heap read in SquashFS archive handler (bsc#1267862). * CVE-2026-48111: off-by-one out-of-bounds read in ParseDepedencyExpression function (bsc#1267863). * CVE-2026-48112: heap out-of-bounds read in BSD SYMDEF parser (bsc#1267864). Changes: * linux version of 7-Zip can use huge pages (2 MB pages). It can increase compression speed for 10% for 7z/xz/LZMA/LZMA2 compression. * new-spo[d|c|r] switch specifies the path generation mode for the output directory for archive extraction. The output directory path is generated from the path specified in the -o{dir_path} switch and the name of the archive being unpacked. -spod : for Linux/Posix/macOS: -o{dir_path} specifies the direct path to the output directory. The asterisk (_) character in {dir_path} will not be replaced by the archive name. -spoc : 7-Zip will concatenate the path specified in -o{dir_path} with the archive name to form the final path to the output directory. -spor : 7-Zip will replace asterisk (_) character in the path specified in the -o{dir_path} with the archive name. This is the default option. * some bugs were fixed. * Update to 26.00: * improved code for ZIP, CPIO, RAR, UFD, QCOW, Compound. * 7-Zip File Manager: improved sorting order of the file list. It uses file name as secondary sorting key.: * 7-Zip File Manager: improved Benchmark to support systems with more than 64 CPU threads. * bug fixed: 7-Zip could not correctly extract TAR archives containing sparse files ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1051=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1051=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * 7zip-26.01-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * 7zip-26.01-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48092.html * https://www.suse.com/security/cve/CVE-2026-48095.html * https://www.suse.com/security/cve/CVE-2026-48101.html * https://www.suse.com/security/cve/CVE-2026-48102.html *https://www.suse.com/security/cve/CVE-2026-48103.html * https://www.suse.com/security/cve/CVE-2026-48104.html * https://www.suse.com/security/cve/CVE-2026-48111.html * https://www.suse.com/security/cve/CVE-2026-48112.html * https://bugzilla.suse.com/show_bug.cgi?id=1267421 * https://bugzilla.suse.com/show_bug.cgi?id=1267858 * https://bugzilla.suse.com/show_bug.cgi?id=1267859 * https://bugzilla.suse.com/show_bug.cgi?id=1267860 * https://bugzilla.suse.com/show_bug.cgi?id=1267861 * https://bugzilla.suse.com/show_bug.cgi?id=1267862 * https://bugzilla.suse.com/show_bug.cgi?id=1267863 * https://bugzilla.suse.com/show_bug.cgi?id=1267864 . Address eight vulnerabilities with this important 7zip security update for SUSE. Enhance system integrity.. SUSE update 7zip vulnerabilities important security. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities can now be installed.. # Security update for 7zip Announcement ID: SUSE-SU-2026:2696-1 Release Date: 2026-06-30T09:10:05Z Rating: important References: * bsc#1267421 * bsc#1267858 * bsc#1267859 * bsc#1267860 * bsc#1267861 * bsc#1267862 * bsc#1267863 * bsc#1267864 Cross-References: * CVE-2026-48092 * CVE-2026-48095 * CVE-2026-48101 * CVE-2026-48102 * CVE-2026-48103 * CVE-2026-48104 * CVE-2026-48111 * CVE-2026-48112 CVSS scores: * CVE-2026-48092 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48092 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48092 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-48095 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-48095 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-48101 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48101 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48102 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48102 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48102 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48102 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48103 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48103 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48103 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48103 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-48104 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48104 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-48104 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-48111 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48111 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48111 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48111 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-48112 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48112 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48112 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for 7zip fixes the following issues Update to26.01: * CVE-2026-48092: Information disclosure in 32-bit builds due to heap memory disclosure (bsc#1267858). * CVE-2026-48095: Heap buffer overflow via NTFS compressed stream buffer under-allocation (bsc#1267421). * CVE-2026-48101: Information Disclosure via uninitialized memory in UEFI capsule parser (bsc#1267859). * CVE-2026-48102: Information disclosure and denial of service via crafted UDF image (bsc#1267860). * CVE-2026-48103: off-by-one heap out-of-bounds read (bsc#1267861). * CVE-2026-48104: Uninitialized heap read in SquashFS archive handler (bsc#1267862). * CVE-2026-48111: off-by-one out-of-bounds read in ParseDepedencyExpression function (bsc#1267863). * CVE-2026-48112: heap out-of-bounds read in BSD SYMDEF parser (bsc#1267864). Changes: * linux version of 7-Zip can use huge pages (2 MB pages). It can increase compression speed for 10% for 7z/xz/LZMA/LZMA2 compression. * new -spo[d|c|r] switch specifies the path generation mode for the output directory for archive extraction. The output directory path is generated from the path specified in the -o{dir_path} switch and the name of the archive being unpacked. -spod : for Linux/Posix/macOS: -o{dir_path} specifies the direct path to the output directory. The asterisk (_) character in {dir_path} will not be replaced by the archive name. -spoc : 7-Zip will concatenate the path specified in -o{dir_path} with the archive name to form the final path to the output directory. -spor : 7-Zip will replace asterisk (_) character in the path specified in the -o{dir_path} with the archive name. This is the default option. * improved code for ZIP, CPIO, RAR, UFD, QCOW, Compound. * 7-Zip File Manager: improved sorting order of the file list. It uses file name as secondary sorting key.: * 7-Zip File Manager: improved Benchmark to support systems with more than 64 CPU threads. * bug fixed: 7-Zip could not correctly extract TAR archives containing sparse files ##Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2696=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2696=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2696=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2696=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2696=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2696=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2696=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2696=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2696=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2696=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2696=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2696=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * 7zip-26.01-150400.9.6.1 * openSUSE Leap 15.4(aarch64 i586 ppc64le s390x x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * 7zip-26.01-150400.9.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * 7zip-26.01-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48092.html * https://www.suse.com/security/cve/CVE-2026-48095.html * https://www.suse.com/security/cve/CVE-2026-48101.html * https://www.suse.com/security/cve/CVE-2026-48102.html * https://www.suse.com/security/cve/CVE-2026-48103.html * https://www.suse.com/security/cve/CVE-2026-48104.html * https://www.suse.com/security/cve/CVE-2026-48111.html * https://www.suse.com/security/cve/CVE-2026-48112.html * https://bugzilla.suse.com/show_bug.cgi?id=1267421 * https://bugzilla.suse.com/show_bug.cgi?id=1267858 * https://bugzilla.suse.com/show_bug.cgi?id=1267859 * https://bugzilla.suse.com/show_bug.cgi?id=1267860 * https://bugzilla.suse.com/show_bug.cgi?id=1267861 * https://bugzilla.suse.com/show_bug.cgi?id=1267862 * https://bugzilla.suse.com/show_bug.cgi?id=1267863 * https://bugzilla.suse.com/show_bug.cgi?id=1267864 . # Security update for 7zip Announcement ID: SUSE-SU-2026:2696-1 Release Date: 2026-06-30T09:10:05Z R. update, solves, eight, vulnerabilities, installed, security, announc. . Severity: Important.LinuxSecurity.com Team
An update that solves eight vulnerabilities can now be installed.. # Security update for 7zip Announcement ID: SUSE-SU-2026:2696-1 Release Date: 2026-06-30T09:10:05Z Rating: important References: * bsc#1267421 * bsc#1267858 * bsc#1267859 * bsc#1267860 * bsc#1267861 * bsc#1267862 * bsc#1267863 * bsc#1267864 Cross-References: * CVE-2026-48092 * CVE-2026-48095 * CVE-2026-48101 * CVE-2026-48102 * CVE-2026-48103 * CVE-2026-48104 * CVE-2026-48111 * CVE-2026-48112 CVSS scores: * CVE-2026-48092 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48092 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48092 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-48095 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-48095 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-48101 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48101 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48102 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48102 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48102 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48102 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48103 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48103 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48103 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48103 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-48104 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48104 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-48104 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-48111 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48111 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48111 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48111 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-48112 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48112 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48112 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for 7zip fixes the following issues Update to26.01: * CVE-2026-48092: Information disclosure in 32-bit builds due to heap memory disclosure (bsc#1267858). * CVE-2026-48095: Heap buffer overflow via NTFS compressed stream buffer under-allocation (bsc#1267421). * CVE-2026-48101: Information Disclosure via uninitialized memory in UEFI capsule parser (bsc#1267859). * CVE-2026-48102: Information disclosure and denial of service via crafted UDF image (bsc#1267860). * CVE-2026-48103: off-by-one heap out-of-bounds read (bsc#1267861). * CVE-2026-48104: Uninitialized heap read in SquashFS archive handler (bsc#1267862). * CVE-2026-48111: off-by-one out-of-bounds read in ParseDepedencyExpression function (bsc#1267863). * CVE-2026-48112: heap out-of-bounds read in BSD SYMDEF parser (bsc#1267864). Changes: * linux version of 7-Zip can use huge pages (2 MB pages). It can increase compression speed for 10% for 7z/xz/LZMA/LZMA2 compression. * new -spo[d|c|r] switch specifies the path generation mode for the output directory for archive extraction. The output directory path is generated from the path specified in the -o{dir_path} switch and the name of the archive being unpacked. -spod : for Linux/Posix/macOS: -o{dir_path} specifies the direct path to the output directory. The asterisk (_) character in {dir_path} will not be replaced by the archive name. -spoc : 7-Zip will concatenate the path specified in -o{dir_path} with the archive name to form the final path to the output directory. -spor : 7-Zip will replace asterisk (_) character in the path specified in the -o{dir_path} with the archive name. This is the default option. * improved code for ZIP, CPIO, RAR, UFD, QCOW, Compound. * 7-Zip File Manager: improved sorting order of the file list. It uses file name as secondary sorting key.: * 7-Zip File Manager: improved Benchmark to support systems with more than 64 CPU threads. * bug fixed: 7-Zip could not correctly extract TAR archives containing sparse files ##Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2696=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2696=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2696=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2696=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2696=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2696=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2696=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2696=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2696=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2696=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2696=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2696=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * 7zip-26.01-150400.9.6.1 * openSUSE Leap 15.4(aarch64 i586 ppc64le s390x x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * 7zip-26.01-150400.9.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * 7zip-26.01-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * 7zip-26.01-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48092.html * https://www.suse.com/security/cve/CVE-2026-48095.html * https://www.suse.com/security/cve/CVE-2026-48101.html * https://www.suse.com/security/cve/CVE-2026-48102.html * https://www.suse.com/security/cve/CVE-2026-48103.html * https://www.suse.com/security/cve/CVE-2026-48104.html * https://www.suse.com/security/cve/CVE-2026-48111.html * https://www.suse.com/security/cve/CVE-2026-48112.html * https://bugzilla.suse.com/show_bug.cgi?id=1267421 * https://bugzilla.suse.com/show_bug.cgi?id=1267858 * https://bugzilla.suse.com/show_bug.cgi?id=1267859 * https://bugzilla.suse.com/show_bug.cgi?id=1267860 * https://bugzilla.suse.com/show_bug.cgi?id=1267861 * https://bugzilla.suse.com/show_bug.cgi?id=1267862 * https://bugzilla.suse.com/show_bug.cgi?id=1267863 * https://bugzilla.suse.com/show_bug.cgi?id=1267864 . Eight vulnerabilities solved in a security update for 7zip affecting multiple SUSE products. Immediate patch recommended.. SUSE security update, 7zip vulnerabilities, important patches. . Severity:Important. LinuxSecurity.com Team
Fixes CVE-2026-48092: Information disclosure in 32-bit builds Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF image. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-f36864b408 2026-06-16 01:10:28.203233+00:00 -------------------------------------------------------------------------------- Name : 7zip Product : Fedora 43 Version : 26.01 Release : 1.fc43 URL : https://7-zip.org Summary : A file archiver Description : 7-Zip is a file archiver with a high compression ratio. The main features of 7-Zip are: * High compression ratio in 7z format with LZMA and LZMA2 compression * Supported formats: * Packing / unpacking: 7z, XZ, BZIP2, GZIP, TAR, ZIP and WIM * Unpacking only: AR, ARJ, CAB, CHM, CPIO, CramFS, DMG, EXT, FAT, GPT, HFS, IHEX, ISO, LZH, LZMA, MBR, MSI, NSIS, NTFS, QCOW2, RPM, SquashFS, UDF, UEFI, VDI, VHD, VMDK, WIM, XAR and Z. * For ZIP and GZIP formats, 7-Zip provides a compression ratio that is 2-10 % better than the ratio provided by PKZip and WinZip * Strong AES-256 encryption in 7z and ZIP formats * Powerful command line version -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-48092: Information disclosure in 32-bit builds Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF image Fixes CVE-2026-48103: Off-by-one buffer over-read in WIM archive handler Fixes CVE-2026-48104: Uninitialized heap read in SquashFS archive handler Fixes CVE-2026-48111: Off-by-one OOB read in UEFI firmware image parser Fixes CVE-2026-48112: Heap-based buffer over-read in Ar handler BSD SYMDEFparser -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 15 2026 Michel Lind - 26.01-1 - Update to 26.01; Resolves: rhbz#2440915 - Fixes CVE-2026-48092: Information disclosure in 32-bit builds - Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler - Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser - Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF image - Fixes CVE-2026-48103: Off-by-one buffer over-read in WIM archive handler - Fixes CVE-2026-48104: Uninitialized heap read in SquashFS archive handler - Fixes CVE-2026-48111: Off-by-one OOB read in UEFI firmware image parser - Fixes CVE-2026-48112: Heap-based buffer over-read in Ar handler BSD SYMDEF parser * Sun May 17 2026 Byoungchan Lee - 25.01-6 - Handle /bin/7z when locating the libexec plugin * Wed Feb 11 2026 Yaakov Selkowitz - 25.01-5 - Respect %_prefix * Wed Feb 11 2026 Yaakov Selkowitz - 25.01-4 - Fix build with GCC 16 * Fri Jan 16 2026 Fedora Release Engineering - 25.01-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Jan 16 2026 Fedora Release Engineering - 25.01-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373874 - 7z cannot find library when invoked with full path: Codec Load Error: /usr/bin/7z.so : errno=2 : No such file or directory https://bugzilla.redhat.com/show_bug.cgi?id=2373874 [ 2 ] Bug #2433842 - 7zip: FTBFS in Fedora rawhide/f44 https://bugzilla.redhat.com/show_bug.cgi?id=2433842 [ 3 ] Bug #2478240 - 7zip: `/bin/7z` fails to load codecs when `/bin` is a symlink to `/usr/bin` https://bugzilla.redhat.com/show_bug.cgi?id=2478240 [ 4 ] Bug #2485479 - CVE-2026-48092 7zip: 7-Zip: Information disclosure in 32-bit builds due to heap memory disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485479 [ 5 ] Bug #2485481 - CVE-2026-48095 7zip: 7-Zip: Arbitrary code execution via heap buffer overflow in NTFS handler [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485481 [ 6 ] Bug #2485489 - CVE-2026-48102 7zip: 7-Zip: Information disclosure and denial of service via crafted UDF image [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485489 [ 7 ] Bug #2485492 - CVE-2026-48101 7zip: 7-Zip: Information Disclosure via uninitialized memory in UEFI capsule parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485492 [ 8 ] Bug #2486337 - CVE-2026-48103 7zip: off-by-one heap-based buffer over-read in the WIM archive handler [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486337 [ 9 ] Bug #2486339 - CVE-2026-48104 7zip: uninitialized heap read in the SquashFS archive handler [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486339 [ 10 ] Bug #2486344 - CVE-2026-48111 7zip: off-by-one out-of-bounds read in the UEFI firmware image parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486344 [ 11 ] Bug #2486347 - CVE-2026-48112 7zip: heap-based buffer over-read in the Ar handler BSD SYMDEF parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486347 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f36864b408' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fixes CVE-2026-48092: Information disclosure in 32-bit builds Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF image. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4be7569210 2026-06-16 01:01:54.934669+00:00 -------------------------------------------------------------------------------- Name : 7zip Product : Fedora 44 Version : 26.01 Release : 1.fc44 URL : https://7-zip.org Summary : A file archiver Description : 7-Zip is a file archiver with a high compression ratio. The main features of 7-Zip are: * High compression ratio in 7z format with LZMA and LZMA2 compression * Supported formats: * Packing / unpacking: 7z, XZ, BZIP2, GZIP, TAR, ZIP and WIM * Unpacking only: AR, ARJ, CAB, CHM, CPIO, CramFS, DMG, EXT, FAT, GPT, HFS, IHEX, ISO, LZH, LZMA, MBR, MSI, NSIS, NTFS, QCOW2, RPM, SquashFS, UDF, UEFI, VDI, VHD, VMDK, WIM, XAR and Z. * For ZIP and GZIP formats, 7-Zip provides a compression ratio that is 2-10 % better than the ratio provided by PKZip and WinZip * Strong AES-256 encryption in 7z and ZIP formats * Powerful command line version -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-48092: Information disclosure in 32-bit builds Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF image Fixes CVE-2026-48103: Off-by-one buffer over-read in WIM archive handler Fixes CVE-2026-48104: Uninitialized heap read in SquashFS archive handler Fixes CVE-2026-48111: Off-by-one OOB read in UEFI firmware image parser Fixes CVE-2026-48112: Heap-based buffer over-read in Ar handler BSD SYMDEFparser -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 15 2026 Michel Lind - 26.01-1 - Update to 26.01; Resolves: rhbz#2440915 - Fixes CVE-2026-48092: Information disclosure in 32-bit builds - Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler - Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser - Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF image - Fixes CVE-2026-48103: Off-by-one buffer over-read in WIM archive handler - Fixes CVE-2026-48104: Uninitialized heap read in SquashFS archive handler - Fixes CVE-2026-48111: Off-by-one OOB read in UEFI firmware image parser - Fixes CVE-2026-48112: Heap-based buffer over-read in Ar handler BSD SYMDEF parser * Sun May 17 2026 Byoungchan Lee - 25.01-6 - Handle /bin/7z when locating the libexec plugin -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373874 - 7z cannot find library when invoked with full path: Codec Load Error: /usr/bin/7z.so : errno=2 : No such file or directory https://bugzilla.redhat.com/show_bug.cgi?id=2373874 [ 2 ] Bug #2433842 - 7zip: FTBFS in Fedora rawhide/f44 https://bugzilla.redhat.com/show_bug.cgi?id=2433842 [ 3 ] Bug #2478240 - 7zip: `/bin/7z` fails to load codecs when `/bin` is a symlink to `/usr/bin` https://bugzilla.redhat.com/show_bug.cgi?id=2478240 [ 4 ] Bug #2485479 - CVE-2026-48092 7zip: 7-Zip: Information disclosure in 32-bit builds due to heap memory disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485479 [ 5 ] Bug #2485481 - CVE-2026-48095 7zip: 7-Zip: Arbitrary code execution via heap buffer overflow in NTFS handler [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485481 [ 6 ] Bug #2485489 - CVE-2026-48102 7zip: 7-Zip: Information disclosure and denial of service via crafted UDF image [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485489 [ 7 ] Bug #2485492 - CVE-2026-48101 7zip: 7-Zip: Information Disclosure via uninitialized memory in UEFI capsule parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485492 [ 8 ] Bug #2486337 - CVE-2026-48103 7zip: off-by-one heap-based buffer over-read in the WIM archive handler [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486337 [ 9 ] Bug #2486339 - CVE-2026-48104 7zip: uninitialized heap read in the SquashFS archive handler [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486339 [ 10 ] Bug #2486344 - CVE-2026-48111 7zip: off-by-one out-of-bounds read in the UEFI firmware image parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486344 [ 11 ] Bug #2486347 - CVE-2026-48112 7zip: heap-based buffer over-read in the Ar handler BSD SYMDEF parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486347 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4be7569210' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.