CVE-2025-53816: GHSL-2025-058 - 7-Zip Multi-byte write heap buffer overflow in NCompress::NRar5::CDecoder
Published Jul 17, 2025
·Updated
7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.
Affected Software
2 affected components
7-Zip 7-Zip<25.0.0
7-Zip 7-Zip<25.00
Event History
Jul 17, 2025
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-53816?
CVE-2025-53816 is classified as a critical vulnerability due to its potential for memory corruption and denial of service.
2
How do I fix CVE-2025-53816?
To fix CVE-2025-53816, update 7-Zip to version 25.0.0 or later.
3
What types of systems are affected by CVE-2025-53816?
CVE-2025-53816 affects all versions of 7-Zip prior to 25.0.0.
4
What can happen if I don't address CVE-2025-53816?
If unaddressed, CVE-2025-53816 may lead to memory corruption and potential denial of service conditions in affected applications.
5
Are there any known exploits for CVE-2025-53816?
As of now, there are no publicly available exploit details specifically targeting CVE-2025-53816.