SUSE-SU-2026:22347-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202622347-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22347-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:22347-1
Upstream
CVE (8)
  • CVE-2026-48092
  • CVE-2026-48095
  • CVE-2026-48101
  • CVE-2026-48102
  • CVE-2026-48103
  • CVE-2026-48104
  • CVE-2026-48111
  • CVE-2026-48112
Related
Published
2026-06-23T12:43:00Z
Modified
2026-07-02T18:24:12Z
Summary
Security update for 7zip
Details

This update for 7zip fixes the following issues

Update to 26.01:

  • CVE-2026-48092: Information disclosure in 32-bit builds due to heap memory disclosure (bsc#1267858).
  • CVE-2026-48095: Heap buffer overflow via NTFS compressed stream buffer under-allocation (bsc#1267421).
  • CVE-2026-48101: Information Disclosure via uninitialized memory in UEFI capsule parser (bsc#1267859).
  • CVE-2026-48102: Information disclosure and denial of service via crafted UDF image (bsc#1267860).
  • CVE-2026-48103: off-by-one heap out-of-bounds read (bsc#1267861).
  • CVE-2026-48104: Uninitialized heap read in SquashFS archive handler (bsc#1267862).
  • CVE-2026-48111: off-by-one out-of-bounds read in ParseDepedencyExpression function (bsc#1267863).
  • CVE-2026-48112: heap out-of-bounds read in BSD SYMDEF parser (bsc#1267864).

Changes:

  • linux version of 7-Zip can use huge pages (2 MB pages). It can increase compression speed for 10% for 7z/xz/LZMA/LZMA2 compression.
  • new -spo[d|c|r] switch specifies the path generation mode for the output directory for archive extraction. The output directory path is generated from the path specified in the -o{dir_path} switch and the name of the archive being unpacked. -spod : for Linux/Posix/macOS: -o{dir_path} specifies the direct path to the output directory. The asterisk () character in {dir_path} will not be replaced by the archive name. -spoc : 7-Zip will concatenate the path specified in -o{dir_path} with the archive name to form the final path to the output directory. -spor : 7-Zip will replace asterisk () character in the path specified in the -o{dir_path} with the archive name. This is the default option.
  • some bugs were fixed.
  • Update to 26.00:
  • improved code for ZIP, CPIO, RAR, UFD, QCOW, Compound.
  • 7-Zip File Manager: improved sorting order of the file list. It uses file name as secondary sorting key.:
  • 7-Zip File Manager: improved Benchmark to support systems with more than 64 CPU threads.
  • bug fixed: 7-Zip could not correctly extract TAR archives containing sparse files
References

Affected packages

SUSE:Linux Enterprise Server 16.0 / 7zip

Package

Name
7zip
Purl
pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20Server%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.01-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "7zip":  "26.01-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22347-1.json"

SUSE:Linux Enterprise Server for SAP applications 16.0 / 7zip

Package

Name
7zip
Purl
pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.01-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "7zip":  "26.01-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22347-1.json"