USN-7438-1: 7-Zip vulnerabilities

Publication date

15 April 2025

Overview

Several security issues were fixed in 7-Zip.


Packages

  • 7zip - 7-Zip file archiver with a high compression ratio

Details

Igor Pavlov discovered that 7-Zip had several memory-related issues.
An attacker could possibly use these issues to cause 7-Zip to crash,
resulting in a denial of service, or execute arbitrary code.
(CVE-2023-52168, CVE-2023-52169)

Igor Pavlov discovered that 7-Zip had several memory-related issues.
An attacker could possibly use these issues to cause 7-Zip to crash,
resulting in a denial of service, or execute arbitrary code.
(CVE-2023-52168, CVE-2023-52169)

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
24.04 noble 7zip –  23.01+dfsg-11ubuntu0.1~esm1  
7zip-standalone –  23.01+dfsg-11ubuntu0.1~esm1  
22.04 jammy 7zip –  21.07+dfsg-4ubuntu0.1~esm1  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›