First published: Sat Apr 19 2025(Updated: )
7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
7-Zip | <=24.09 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-47111 is classified as medium.
To fix CVE-2022-47111, upgrade to 7-Zip version 24.10 or later.
CVE-2022-47111 affects 7-Zip versions up to and including 24.09.
CVE-2022-47111 involves certain invalid xz files, specifically those dealing with block flags and reserved bits.
CVE-2022-47111 may cause unintended behavior but is not directly exploitable for remote code execution.