stable

7zip-26.01-1.el10_2

FEDORA-EPEL-2026-8d909527ba created by salimma 3 months ago for Fedora EPEL 10.2
  • Fixes CVE-2026-48092: Information disclosure in 32-bit builds
  • Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler
  • Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser
  • Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF image
  • Fixes CVE-2026-48103: Off-by-one buffer over-read in WIM archive handler
  • Fixes CVE-2026-48104: Uninitialized heap read in SquashFS archive handler
  • Fixes CVE-2026-48111: Off-by-one OOB read in UEFI firmware image parser
  • Fixes CVE-2026-48112: Heap-based buffer over-read in Ar handler BSD SYMDEF parser

This update has been submitted for testing by salimma.

3 months ago

This update's test gating status has been changed to 'ignored'.

3 months ago
User Icon dcavalca provided feedback 3 months ago
karma
BZ#2373874 7z cannot find library when invoked with full path: Codec Load Error: /usr/bin/7z.so : errno=2 : No such file or directory
BZ#2478240 7zip: `/bin/7z` fails to load codecs when `/bin` is a symlink to `/usr/bin`
BZ#2485480 CVE-2026-48092 7zip: 7-Zip: Information disclosure in 32-bit builds due to heap memory disclosure [epel-all]
BZ#2485482 CVE-2026-48095 7zip: 7-Zip: Arbitrary code execution via heap buffer overflow in NTFS handler [epel-all]
BZ#2485490 CVE-2026-48101 7zip: 7-Zip: Information Disclosure via uninitialized memory in UEFI capsule parser [epel-all]
BZ#2485491 CVE-2026-48102 7zip: 7-Zip: Information disclosure and denial of service via crafted UDF image [epel-all]
BZ#2486335 CVE-2026-48103 7zip: off-by-one heap-based buffer over-read in the WIM archive handler [epel-all]
BZ#2486338 CVE-2026-48104 7zip: uninitialized heap read in the SquashFS archive handler [epel-all]
BZ#2486342 CVE-2026-48111 7zip: off-by-one out-of-bounds read in the UEFI firmware image parser [epel-all]
BZ#2486346 CVE-2026-48112 7zip: heap-based buffer over-read in the Ar handler BSD SYMDEF parser [epel-all]
User Icon py0xc3 commented & provided feedback 3 months ago
karma

Works fine: compressing & decompressing files, benchmark. Tested in KVM/QEMU cpu-passthrough on Ryzen 6850U. AlmaLinux 10.2, up to date. CVE's NOT tested.

This update has been submitted for stable by bodhi.

3 months ago

This update has been pushed to stable.

3 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
2
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
2
Stable by Time
7 days
Dates
submitted
3 months ago
in stable
3 months ago
approved
3 months ago
BZ#2373874 7z cannot find library when invoked with full path: Codec Load Error: /usr/bin/7z.so : errno=2 : No such file or directory
0
1
BZ#2478240 7zip: `/bin/7z` fails to load codecs when `/bin` is a symlink to `/usr/bin`
0
1
BZ#2485480 CVE-2026-48092 7zip: 7-Zip: Information disclosure in 32-bit builds due to heap memory disclosure [epel-all]
0
1
BZ#2485482 CVE-2026-48095 7zip: 7-Zip: Arbitrary code execution via heap buffer overflow in NTFS handler [epel-all]
0
1
BZ#2485490 CVE-2026-48101 7zip: 7-Zip: Information Disclosure via uninitialized memory in UEFI capsule parser [epel-all]
0
1
BZ#2485491 CVE-2026-48102 7zip: 7-Zip: Information disclosure and denial of service via crafted UDF image [epel-all]
0
1
BZ#2486335 CVE-2026-48103 7zip: off-by-one heap-based buffer over-read in the WIM archive handler [epel-all]
0
1
BZ#2486338 CVE-2026-48104 7zip: uninitialized heap read in the SquashFS archive handler [epel-all]
0
1
BZ#2486342 CVE-2026-48111 7zip: off-by-one out-of-bounds read in the UEFI firmware image parser [epel-all]
0
1
BZ#2486346 CVE-2026-48112 7zip: heap-based buffer over-read in the Ar handler BSD SYMDEF parser [epel-all]
0
1

Automated Test Results