Back Linuxsecurity Debian LTS p7zip Critical Buffer Overflow Remote Code Exec DLA-4719
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
To address these security vulnerabilities, whose fixes unfortunately cannot be isolated, this update again replaces p7zip with a recent 7-Zip (now v26.02), slightly modified to make it reasonably compatible with p7zip. Among the fixed vulnerabilities, the following were made public: CVE-2026-14266 XZ decompression heap-based buffer overflow, potentially leading to remote code execution. CVE-2026-58052 RAR5 alternate-stream handling issue, when running on an NTFS filesystem with transparent ADS (Alternate Data Stream) and ADS canonicalization, letting an attacker defeat Mark-of-the-Web warnings and spoof file content. For Debian 11 bullseye, these problems have been fixed in version 16.02+really26.02+dfsg-0+deb11u1. For Debian 12 bookworm, these problems have been fixed in version 16.02+really26.02+dfsg-0+deb12u1. We recommend that you upgrade your p7zip packages. For the detailed security status of p7zip please refer to its security tracker page at:
To address these security vulnerabilities, whose fixes unfortunately cannot be isolated, this update again replaces p7zip with a recent 7-Zip (now v26.02), slightly modified to make it reasonably compatible with p7zip. Among the fixed vulnerabilities, the following were made public: CVE-2026-14266 XZ decompression heap-based buffer overflow, potentially leading to remote code execution. CVE-2026-58052 RAR5 alternate-stream handling issue, when running on an NTFS filesystem with transparent ADS (Alternate Data Stream) and ADS canonicalization, letting an attacker defeat Mark-of-the-Web warnings and spoof file content. For Debian 11 bullseye, these problems have been fixed in version 16.02+really26.02+dfsg-0+deb11u1. For Debian 12 bookworm, these problems have been fixed in version 16.02+really26.02+dfsg-0+deb12u1. We recommend that you upgrade your p7zip packages. For the detailed security status of p7zip please refer to its security tracker page at:
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
