Описание
Security update for 7zip
This update for 7zip fixes the following issue:
- CVE-2026-14266: heap buffer overflow when processing XZ chunked data can lead to remote code execution (bsc#1273065).
Changes for 7zip:
- Updated to 26.02.
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
7zip-26.02-150400.9.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
7zip-26.02-150400.9.9.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
7zip-26.02-150400.9.9.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
7zip-26.02-150400.9.9.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
7zip-26.02-150400.9.9.1
SUSE Linux Enterprise Server 15 SP4-LTSS
7zip-26.02-150400.9.9.1
SUSE Linux Enterprise Server 15 SP5-LTSS
7zip-26.02-150400.9.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS
7zip-26.02-150400.9.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
7zip-26.02-150400.9.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
7zip-26.02-150400.9.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
7zip-26.02-150400.9.9.1
Ссылки
- Link for SUSE-SU-2026:3869-1
- E-Mail link for SUSE-SU-2026:3869-1
- SUSE Security Ratings
- SUSE Bug 1273065
- SUSE CVE CVE-2026-14266 page
Описание
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-30169.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:7zip-26.02-150400.9.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:7zip-26.02-150400.9.9.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:7zip-26.02-150400.9.9.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:7zip-26.02-150400.9.9.1
Ссылки
- CVE-2026-14266
- SUSE Bug 1273065