CVE-2022-47112: Low severity 7-zip vulnerability
Published Apr 19, 2025
·Updated
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.
Affected Software
2 affected components
7-Zip 7-Zip
7-Zip 7-Zip=22.01
Event History
Apr 19, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-47112?
CVE-2022-47112 is classified as a medium severity vulnerability.
2
How does CVE-2022-47112 affect 7-Zip users?
CVE-2022-47112 affects users by not reporting errors for invalid xz files, which can lead to potential data corruption.
3
How do I fix CVE-2022-47112?
To mitigate CVE-2022-47112, users should upgrade to a version of 7-Zip later than 24.09.
4
What versions of 7-Zip are affected by CVE-2022-47112?
CVE-2022-47112 affects all versions of 7-Zip up to and including version 24.09.
5
Is there a workaround for CVE-2022-47112?
There is no known workaround for CVE-2022-47112 other than updating to a patched version.