openSUSE-SU-2026:21038-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21038-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21038-1
Upstream
CVE (8)
  • CVE-2026-48092
  • CVE-2026-48095
  • CVE-2026-48101
  • CVE-2026-48102
  • CVE-2026-48103
  • CVE-2026-48104
  • CVE-2026-48111
  • CVE-2026-48112
Related
Published
2026-06-23T12:46:58Z
Modified
2026-06-30T18:24:37Z
Summary
Security update for 7zip
Details

This update for 7zip fixes the following issues

Update to 26.01:

  • CVE-2026-48092: Information disclosure in 32-bit builds due to heap memory disclosure (bsc#1267858).
  • CVE-2026-48095: Heap buffer overflow via NTFS compressed stream buffer under-allocation (bsc#1267421).
  • CVE-2026-48101: Information Disclosure via uninitialized memory in UEFI capsule parser (bsc#1267859).
  • CVE-2026-48102: Information disclosure and denial of service via crafted UDF image (bsc#1267860).
  • CVE-2026-48103: off-by-one heap out-of-bounds read (bsc#1267861).
  • CVE-2026-48104: Uninitialized heap read in SquashFS archive handler (bsc#1267862).
  • CVE-2026-48111: off-by-one out-of-bounds read in ParseDepedencyExpression function (bsc#1267863).
  • CVE-2026-48112: heap out-of-bounds read in BSD SYMDEF parser (bsc#1267864).

Changes:

  • linux version of 7-Zip can use huge pages (2 MB pages). It can increase compression speed for 10% for 7z/xz/LZMA/LZMA2 compression.
  • new -spo[d|c|r] switch specifies the path generation mode for the output directory for archive extraction. The output directory path is generated from the path specified in the -o{dir_path} switch and the name of the archive being unpacked. -spod : for Linux/Posix/macOS: -o{dir_path} specifies the direct path to the output directory. The asterisk () character in {dir_path} will not be replaced by the archive name. -spoc : 7-Zip will concatenate the path specified in -o{dir_path} with the archive name to form the final path to the output directory. -spor : 7-Zip will replace asterisk () character in the path specified in the -o{dir_path} with the archive name. This is the default option.
  • some bugs were fixed.
  • Update to 26.00:
  • improved code for ZIP, CPIO, RAR, UFD, QCOW, Compound.
  • 7-Zip File Manager: improved sorting order of the file list. It uses file name as secondary sorting key.:
  • 7-Zip File Manager: improved Benchmark to support systems with more than 64 CPU threads.
  • bug fixed: 7-Zip could not correctly extract TAR archives containing sparse files
References

Affected packages

openSUSE:Leap 16.0 / 7zip

Package

Name
7zip
Purl
pkg:rpm/opensuse/7zip&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.01-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "7zip":  "26.01-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21038-1.json"