#1138185 trixie-pu: package 7zip/26.01+dfsg-1~deb13u1

#1138185#5
Date:
2026-05-29 00:51:16 UTC
From:
To:
[ Reason ]
Fix CVE-2026-48095 (heap buffer write overflow)

[ Impact ]
A CVE (CVSS: 8.8/10) is unfixed.

[ Tests ]
Autopkgtest on Salsa CI was successful.
https://salsa.debian.org/debian/7zip/-/pipelines/1096718

[ Risks ]
This patch just update upstream code to v26.01.
Because upstream dose not provide individual fix patch for the CVE.
I recommend to use online for examine this update.
Attached debdiff is compressed because it's too big. (20MB)

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
* Update upstream code to v26.01
* Adjust Debian patch to new upstream code
* Adjust debian/watch file because upstream changes download URL

[ Other info ]
* GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip
https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/
* Examine this update from online
https://salsa.debian.org/debian/7zip/-/compare/debian%2F25.01+dfsg-1_deb13u2...debian%2Ftrixie?from_project_id=61356

#1138185#12
Date:
2026-05-29 02:25:08 UTC
From:
To:
I was added some fixups to debian/gbp.conf to ease maintain trixie update.
* Drop file permission hack
* Configure git-buidpackage for trixie update

Here is new update status:
* Salsa CI
https://salsa.debian.org/debian/7zip/-/pipelines/1096942
* Examine from online
https://salsa.debian.org/debian/7zip/-/compare/debian%2F25.01+dfsg-1_deb13u2...debian%2Ftrixie?from_project_id=61356

#1138185#17
Date:
2026-06-01 19:57:29 UTC
From:
To:
Hi,

FYI, I *think* the debdiff was too big to reach the mailinglist, so
you can as well attach a filtered debdiff to indicate what was needed
to change for the debian/* packaging point of view. I can confirm that
the attachments are in the bug though.

Regards,
Salvatore

#1138185#22
Date:
2026-06-04 13:57:23 UTC
From:
To:
Hello Salvatore,
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138181
Also add more CVEs that fixed by 7zip 26.01 to debian/changelog.
 * CVE-2026-48092: SquashFS Fragment Offset Overflow
 * CVE-2026-48095: Heap Buffer Write Overflow
 * CVE-2026-48101: UEFI Capsule uninitialized heap memory disclosure
 * CVE-2026-48102: UDF Field OOB Read
 * CVE-2026-48103: WIM SecurityId OOB read
 * CVE-2026-48104: SquashFS BlockToNode uninitialized heap read
 * CVE-2026-48111: UEFI DEPEX OOB Read
 * CVE-2026-48112: Ar SYMDEF OOB Read


And here is new and minimized debdiff.
* 7zip_26.01+dfsg-1~deb13u1-debian-b.diff
  "debian/*" files only, ignore space characters change.
* 7zip_26.01+dfsg-1~deb13u1-w.debdiff
  All files, ignore space characters change.

It also examine from online:
* Diffs after importing upstream 26.01 code
https://salsa.debian.org/debian/7zip/-/compare/383103997a449be2086af764cd8fab2006724ef0...debian%2Ftrixie

#1138185#27
Date:
2026-07-02 09:25:27 UTC
From:
To:
AFAIR 7zip-rar in trixie is a plugin for 7zip, and the plugin in trixie
might not work with the proposed backport of the new version?

cu
Adrian

#1138185#32
Date:
2026-07-02 13:21:39 UTC
From:
To:
Hello Adrian,

7zip-rar v26 for 7zip v26 is much better than 7zip-rar v25 for 7zip v26.
But this is not essential. 7zip-rar v25 works on 7zip v26.

7zip plugin interface is not changed since 7zip v23.
So, 7zip-rar v25 works on 7zip v26 at least my trivial autopkgtest on my PC.

This ABI issue was mentioned in salsa.
* Fix ABI mismatch
https://salsa.debian.org/debian/7zip-rar/-/commit/8278619e34601990c264f4277df205089d808280

If you accept 7zip-rar v26 for trixie, I will make 7zip-rar v26 package.
Because using same version for 7zip and 7zip-rar is much better.

#1138185#37
Date:
2026-07-02 13:30:26 UTC
From:
To:
Thanks, it seems I misremembered that.

This is not my decision, I am not a member of the release team.

cu
Adrian

#1138185#42
Date:
2026-07-11 12:33:11 UTC
From:
To:
Hmmm, it's a bit unfortunate that the bookworm 7zip update was accepted
but not this trixie one.

I guess we can close this one and go for a 26.02 update in September for
Debian 13.7.

I don't believe a 7zip-rar update is necessary if there's no
security-related issues to fix (no changes in CPP/7zip/Compress/Rar*
since v25.00).

Cheers!
Sylvain

#1138185#47
Date:
2026-07-16 19:41:18 UTC
From:
To:
Hi,

or if he SRM agree still get this updloaded, exposed in proposed
updates and get a 26.02 update later on on top as needed.

Regards,
Salvatore

#1138185#52
Date:
2026-07-17 03:17:09 UTC
From:
To:
Hello,

Vulnerability fix in 7zip 26.02 update was now disclosed as ZDI-26-444
and CVE-2026-14266.

* https://www.zerodayinitiative.com/advisories/ZDI-26-444/

#1138185#57
Date:
2026-07-18 14:20:30 UTC
From:
To:
Hello,

I was updated trixie code with 7zip 26.02.
Here is minimized debdiff that only includes "debian/" directory.

Examine all diffs from online:
https://salsa.debian.org/debian/7zip/-/compare/debian%2F25.01+dfsg-1_deb13u2...debian%2Ftrixie?from_project_id=61356

#1138185#62
Date:
2026-08-22 19:12:31 UTC
From:
To:
Hello,

I was updated trixie code to fix Debian bug 1144903.

Here is minimized debdiff that only includes "debian/" directory.

Examine all diffs from online:
https://salsa.debian.org/debian/7zip/-/compare/debian%2F25.01+dfsg-1_deb13u2...debian%2Ftrixie?from_project_id=61356