Skip to content
Debian LTS p7zip Critical Buffer Overflow Remote Code Exec DLA-4719

Debian LTS p7zip Critical Buffer Overflow Remote Code Exec DLA-4719

Linuxsecurity LinuxSecurity Advisories August 5, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

To address these security vulnerabilities, whose fixes unfortunately cannot be isolated, this update again replaces p7zip with a recent 7-Zip (now v26.02), slightly modified to make it reasonably compatible with p7zip. Among the fixed vulnerabilities, the following were made public: CVE-2026-14266 XZ decompression heap-based buffer overflow, potentially leading to remote code execution. CVE-2026-58052 RAR5 alternate-stream handling issue, when running on an NTFS filesystem with transparent ADS (Alternate Data Stream) and ADS canonicalization, letting an attacker defeat Mark-of-the-Web warnings and spoof file content. For Debian 11 bullseye, these problems have been fixed in version 16.02+really26.02+dfsg-0+deb11u1. For Debian 12 bookworm, these problems have been fixed in version 16.02+really26.02+dfsg-0+deb12u1. We recommend that you upgrade your p7zip packages. For the detailed security status of p7zip please refer to its security tracker page at:

To address these security vulnerabilities, whose fixes unfortunately cannot be isolated, this update again replaces p7zip with a recent 7-Zip (now v26.02), slightly modified to make it reasonably compatible with p7zip. Among the fixed vulnerabilities, the following were made public: CVE-2026-14266 XZ decompression heap-based buffer overflow, potentially leading to remote code execution. CVE-2026-58052 RAR5 alternate-stream handling issue, when running on an NTFS filesystem with transparent ADS (Alternate Data Stream) and ADS canonicalization, letting an attacker defeat Mark-of-the-Web warnings and spoof file content. For Debian 11 bullseye, these problems have been fixed in version 16.02+really26.02+dfsg-0+deb11u1. For Debian 12 bookworm, these problems have been fixed in version 16.02+really26.02+dfsg-0+deb12u1. We recommend that you upgrade your p7zip packages. For the detailed security status of p7zip please refer to its security tracker page at:

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Attack Types (1)

Platforms (1)