First published: Sat Apr 19 2025(Updated: )
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
7-Zip | <=24.09 | |
7-Zip |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47112 is classified as a medium severity vulnerability.
CVE-2022-47112 affects users by not reporting errors for invalid xz files, which can lead to potential data corruption.
To mitigate CVE-2022-47112, users should upgrade to a version of 7-Zip later than 24.09.
CVE-2022-47112 affects all versions of 7-Zip up to and including version 24.09.
There is no known workaround for CVE-2022-47112 other than updating to a patched version.