- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- YOKOTA Hiroshi
- Date:
- 2026-08-22 19:15:01 UTC
- Severity:
- normal
- Tags:
[ Reason ] Fix CVE-2026-48095 (heap buffer write overflow) [ Impact ] A CVE (CVSS: 8.8/10) is unfixed. [ Tests ] Autopkgtest on Salsa CI was successful. https://salsa.debian.org/debian/7zip/-/pipelines/1096718 [ Risks ] This patch just update upstream code to v26.01. Because upstream dose not provide individual fix patch for the CVE. I recommend to use online for examine this update. Attached debdiff is compressed because it's too big. (20MB) [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable [ Changes ] * Update upstream code to v26.01 * Adjust Debian patch to new upstream code * Adjust debian/watch file because upstream changes download URL [ Other info ] * GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/ * Examine this update from online https://salsa.debian.org/debian/7zip/-/compare/debian%2F25.01+dfsg-1_deb13u2...debian%2Ftrixie?from_project_id=61356
I was added some fixups to debian/gbp.conf to ease maintain trixie update. * Drop file permission hack * Configure git-buidpackage for trixie update Here is new update status: * Salsa CI https://salsa.debian.org/debian/7zip/-/pipelines/1096942 * Examine from online https://salsa.debian.org/debian/7zip/-/compare/debian%2F25.01+dfsg-1_deb13u2...debian%2Ftrixie?from_project_id=61356
Hi, FYI, I *think* the debdiff was too big to reach the mailinglist, so you can as well attach a filtered debdiff to indicate what was needed to change for the debian/* packaging point of view. I can confirm that the attachments are in the bug though. Regards, Salvatore
Hello Salvatore, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138181 Also add more CVEs that fixed by 7zip 26.01 to debian/changelog. * CVE-2026-48092: SquashFS Fragment Offset Overflow * CVE-2026-48095: Heap Buffer Write Overflow * CVE-2026-48101: UEFI Capsule uninitialized heap memory disclosure * CVE-2026-48102: UDF Field OOB Read * CVE-2026-48103: WIM SecurityId OOB read * CVE-2026-48104: SquashFS BlockToNode uninitialized heap read * CVE-2026-48111: UEFI DEPEX OOB Read * CVE-2026-48112: Ar SYMDEF OOB Read And here is new and minimized debdiff. * 7zip_26.01+dfsg-1~deb13u1-debian-b.diff "debian/*" files only, ignore space characters change. * 7zip_26.01+dfsg-1~deb13u1-w.debdiff All files, ignore space characters change. It also examine from online: * Diffs after importing upstream 26.01 code https://salsa.debian.org/debian/7zip/-/compare/383103997a449be2086af764cd8fab2006724ef0...debian%2Ftrixie
AFAIR 7zip-rar in trixie is a plugin for 7zip, and the plugin in trixie might not work with the proposed backport of the new version? cu Adrian
Hello Adrian, 7zip-rar v26 for 7zip v26 is much better than 7zip-rar v25 for 7zip v26. But this is not essential. 7zip-rar v25 works on 7zip v26. 7zip plugin interface is not changed since 7zip v23. So, 7zip-rar v25 works on 7zip v26 at least my trivial autopkgtest on my PC. This ABI issue was mentioned in salsa. * Fix ABI mismatch https://salsa.debian.org/debian/7zip-rar/-/commit/8278619e34601990c264f4277df205089d808280 If you accept 7zip-rar v26 for trixie, I will make 7zip-rar v26 package. Because using same version for 7zip and 7zip-rar is much better.
Thanks, it seems I misremembered that. This is not my decision, I am not a member of the release team. cu Adrian
Hmmm, it's a bit unfortunate that the bookworm 7zip update was accepted but not this trixie one. I guess we can close this one and go for a 26.02 update in September for Debian 13.7. I don't believe a 7zip-rar update is necessary if there's no security-related issues to fix (no changes in CPP/7zip/Compress/Rar* since v25.00). Cheers! Sylvain
Hi, or if he SRM agree still get this updloaded, exposed in proposed updates and get a 26.02 update later on on top as needed. Regards, Salvatore
Hello, Vulnerability fix in 7zip 26.02 update was now disclosed as ZDI-26-444 and CVE-2026-14266. * https://www.zerodayinitiative.com/advisories/ZDI-26-444/
Hello, I was updated trixie code with 7zip 26.02. Here is minimized debdiff that only includes "debian/" directory. Examine all diffs from online: https://salsa.debian.org/debian/7zip/-/compare/debian%2F25.01+dfsg-1_deb13u2...debian%2Ftrixie?from_project_id=61356
Hello, I was updated trixie code to fix Debian bug 1144903. Here is minimized debdiff that only includes "debian/" directory. Examine all diffs from online: https://salsa.debian.org/debian/7zip/-/compare/debian%2F25.01+dfsg-1_deb13u2...debian%2Ftrixie?from_project_id=61356