Back Linuxsecurity Debian LTS 7zip Important Buffer Overflow Remote Code Execution DLA-4718
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
Among the fixed vulnerabilities, the following were made public: CVE-2026-14266 XZ decompression heap-based buffer overflow, potentially leading to remote code execution. CVE-2026-58052 RAR5 alternate-stream handling issue, when running on an NTFS filesystem with transparent ADS (Alternate Data Stream) and ADS canonicalization, letting an attacker defeat Mark-of-the-Web warnings and spoof file content. For Debian 12 bookworm, these problems have been fixed in version 22.01+really26.02+dfsg-0+deb12u1. We recommend that you upgrade your 7zip packages. For the detailed security status of 7zip please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
Among the fixed vulnerabilities, the following were made public: CVE-2026-14266 XZ decompression heap-based buffer overflow, potentially leading to remote code execution. CVE-2026-58052 RAR5 alternate-stream handling issue, when running on an NTFS filesystem with transparent ADS (Alternate Data Stream) and ADS canonicalization, letting an attacker defeat Mark-of-the-Web warnings and spoof file content. For Debian 12 bookworm, these problems have been fixed in version 22.01+really26.02+dfsg-0+deb12u1. We recommend that you upgrade your 7zip packages. For the detailed security status of 7zip please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
