{"id":"ECHO-c41c-0d0a-92ad","summary":"Low-severity (CVSS 3.1 2.5, CWE-754, Debian \"unimportant\") error-reporting\nquirk: 7-Zip 22.01 silently returns OK for an xz file with reserved bits\nset in the stream flags instead of flagging it. No memory-safety impact.\nNVD's affected-version data is pinned to exactly 22.01 and states \"Some\nlater versions are unaffected\"; remediated upstream by version currency,\nnot by a separate patch, so there is nothing to backport. Verified against\nthe reporter's PoC (boofish/semantic-bugs pocs/poc2.xz) on this build's\n25.01 binaries: the standalone 7za/7zr hard-error (exit 2, \"Is not\narchive\") and 7zz/7z no longer silently accept it (now emit \"Warnings: 1\"),\nso the reported silent-acceptance behavior does not reproduce.\n","modified":"2026-09-15T03:33:36.201371872Z","published":"2026-07-06T14:55:23.579Z","withdrawn":"2026-07-19T16:41:19.923Z","upstream":["CVE-2022-47112"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2022-47112"}],"affected":[{"package":{"name":"7zip","ecosystem":"Echo","purl":"pkg:deb/echo/7zip"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.01+dfsg-1~deb13u2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-c41c-0d0a-92ad.json"}}],"schema_version":"1.9.0"}