{"id":"SUSE-SU-2026:2696-1","summary":"Security update for 7zip","details":"This update for 7zip fixes the following issues\n\nUpdate to 26.01:\n\n- CVE-2026-48092: Information disclosure in 32-bit builds due to heap memory disclosure (bsc#1267858).\n- CVE-2026-48095: Heap buffer overflow via NTFS compressed stream buffer under-allocation (bsc#1267421).\n- CVE-2026-48101: Information Disclosure via uninitialized memory in UEFI capsule parser (bsc#1267859).\n- CVE-2026-48102: Information disclosure and denial of service via crafted UDF image (bsc#1267860).\n- CVE-2026-48103: off-by-one heap out-of-bounds read (bsc#1267861).\n- CVE-2026-48104: Uninitialized heap read in SquashFS archive handler (bsc#1267862).\n- CVE-2026-48111: off-by-one out-of-bounds read in ParseDepedencyExpression function (bsc#1267863).\n- CVE-2026-48112: heap out-of-bounds read in BSD SYMDEF parser (bsc#1267864).\n\nChanges:\n\n * linux version of 7-Zip can use huge pages (2 MB pages). It can\n increase compression speed for 10% for 7z/xz/LZMA/LZMA2 compression.\n * new -spo[d|c|r] switch specifies the path generation mode for\n the output directory for archive extraction. The output directory\n path is generated from the path specified in the -o{dir_path}\n switch and the name of the archive being unpacked.\n -spod : for Linux/Posix/macOS: -o{dir_path} specifies the direct\n path to the output directory. The asterisk (*) character\n in {dir_path} will not be replaced by the archive name.\n -spoc : 7-Zip will concatenate the path specified in -o{dir_path}\n with the archive name to form the final path to the output\n directory.\n -spor : 7-Zip will replace asterisk (*) character in the path\n specified in the -o{dir_path} with the archive name.\n This is the default option.\n * improved code for ZIP, CPIO, RAR, UFD, QCOW, Compound.\n * 7-Zip File Manager: improved sorting order of the file list.\n It uses file name as secondary sorting key.:\n * 7-Zip File Manager: improved Benchmark to support systems with more than\n 64 CPU threads.\n * bug fixed: 7-Zip could not correctly extract TAR archives containing sparse\n files\n","modified":"2026-07-01T09:45:06.024787597Z","published":"2026-06-30T09:10:04Z","related":["CVE-2026-48092","CVE-2026-48095","CVE-2026-48101","CVE-2026-48102","CVE-2026-48103","CVE-2026-48104","CVE-2026-48111","CVE-2026-48112"],"upstream":["CVE-2026-48092","CVE-2026-48095","CVE-2026-48101","CVE-2026-48102","CVE-2026-48103","CVE-2026-48104","CVE-2026-48111","CVE-2026-48112"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262696-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267421"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267858"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267859"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267860"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267861"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267862"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267863"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48092"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48095"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48101"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48102"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48103"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48104"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48112"}],"affected":[{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}},{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}},{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}},{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}},{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}},{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}},{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}},{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}},{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}},{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}},{"package":{"name":"7zip","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/7zip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.01-150400.9.6.1"}]}],"ecosystem_specific":{"binaries":[{"7zip":"26.01-150400.9.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2696-1.json"}}],"schema_version":"1.7.5"}