CVE-2025-53816
GHSL-2025-058 - 7-Zip Multi-byte write heap buffer overflow in NCompress::NRar5::CDecoder
CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
31th
7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.
| CWE | CWE-122 |
| Vendor | ipavlov |
| Product | 7-zip |
| Published | Jul 17, 2025 |
| Last Updated | May 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for ipavlov 7-zip
Be the first to know when new unknown vulnerabilities affecting ipavlov 7-zip are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ipavlov / 7-Zip
< 25.0.0
References
securitylab.github.com: https://securitylab.github.com/advisories/GHSL-2025-058_7-Zip/ openwall.com: https://www.openwall.com/lists/oss-security/2025/07/18/1 openwall.com: http://www.openwall.com/lists/oss-security/2025/07/18/1 lists.debian.org: https://lists.debian.org/debian-lts-announce/2026/05/msg00021.html