Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-10443

Опубликовано: 26 июн. 2026
Источник: fstec
CVSS3: 7
CVSS2: 6.2
EPSS Низкий

Описание

Уязвимость функции MixCoder_Code() компонента XZ Decoder архиватора 7-Zip связана с переполнением буфера в динамической памяти. Эксплуатация уязвимости может позволить нарушителю выполнить произвольный код

Вендор

ООО «РусБИТех-Астра»
Павлов Игорь

Наименование ПО

Astra Linux Special Edition
7-Zip

Версия ПО

1.7 (Astra Linux Special Edition)
4.7 (Astra Linux Special Edition)
до 26.02 (7-Zip)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «РусБИТех-Астра» Astra Linux Special Edition 1.7
ООО «РусБИТех-Астра» Astra Linux Special Edition 4.7

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,2)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7)

Возможные меры по устранению уязвимости

Использование рекомендаций:
обновление до версии 26.02 или выше:
https://github.com/4minx/CVE-2026-14266
https://github.com/ip7z/7zip/releases
Для ОС Astra Linux:
обновить пакет bind9 до 1:9.11.38.astra3 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se17-bulletin-2026-0820SE17
Для ОС Astra Linux:
- обновить пакет 7zip до 26.02+dfsg-2.astra1 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se47-bulletin-2026-0907SE47
- обновить пакет p7zip до 16.02+transitional.1 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se47-bulletin-2026-0907SE47

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

EPSS

Процентиль: 53%
0.00742
Низкий

7 High

CVSS3

6.2 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 месяцев назад

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-30169.

CVSS3: 7.8
nvd
около 2 месяцев назад

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-30169.

CVSS3: 7.8
debian
около 2 месяцев назад

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Executio ...

suse-cvrf
28 дней назад

Security update for 7zip

suse-cvrf
25 дней назад

Security update for 7zip

EPSS

Процентиль: 53%
0.00742
Низкий

7 High

CVSS3

6.2 Medium

CVSS2