CVE-2025-53817

NameCVE-2025-53817
Description7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to version 25.0.0, a null pointer dereference in the Compound handler may lead to denial of service. Version 25.0.0 contains a fix cor the issue.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
7zip (PTS)bookworm22.01+dfsg-8+deb12u1vulnerable
trixie24.09+dfsg-8vulnerable
sid25.00+dfsg-1fixed
p7zip (PTS)bookworm, bullseye16.02+dfsg-8vulnerable
trixie, sid16.02+transitional.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
7zipsource(unstable)25.00+dfsg-1unimportant
p7zipsource(unstable)16.02+transitional.1unimportant

Notes

Crash in CLI tool, no security impact
https://securitylab.github.com/advisories/GHSL-2025-059_7-Zip/
https://www.openwall.com/lists/oss-security/2025/07/18/2
Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
depending on 7zip. Mark this version as fixed version.

Search for package or bug name: Reporting problems