CVE-2025-53816

EUVD-2025-21791
7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 48.21%
Affected Products (NVD)
VendorProductVersion
7-zip7-zip
𝑥
< 25.00
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
7zip-rar
forky/non-free
26.02-2
fixed
sid/non-free
26.02-3
fixed
trixie/non-free
25.00+ds-1+deb13u1
fixed
p7zip-rar
bookworm/non-free
16.02+really25.00+ds-0+deb12u1
fixed
bullseye/non-free
vulnerable
bullseye/non-free (security)
16.02+really25.00+ds-0+deb11u1
fixed
trixie/non-free
16.02+transitional.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
7zip
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
not-affected
resolute
not-affected