CVE-2022-47112

7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.
References
Link Resource
https://github.com/boofish/semantic-bugs/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:7-zip:7-zip:22.01:*:*:*:*:*:*:*

History

18 Aug 2025, 16:41

Type Values Removed Values Added
Summary
  • (es) 7-Zip 22.01 no reporta errores para ciertos archivos xz no válidos, relacionados con indicadores de flujo y bits reservados. Algunas versiones posteriores no se ven afectadas.
CPE cpe:2.3:a:7-zip:7-zip:22.01:*:*:*:*:*:*:*
References () https://github.com/boofish/semantic-bugs/ - () https://github.com/boofish/semantic-bugs/ - Exploit, Third Party Advisory
First Time 7-zip
7-zip 7-zip

19 Apr 2025, 22:15

Type Values Removed Values Added
Summary (en) 7-Zip through 24.09 does not report an error for certain invalid xz files, involving stream flags and reserved bits. (en) 7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.

19 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-19 21:15

Updated : 2025-08-18 16:41


NVD link : CVE-2022-47112

Mitre link : CVE-2022-47112

CVE.ORG link : CVE-2022-47112


JSON object : View

Products Affected

7-zip

  • 7-zip
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions