CVE-2025-53817: GHSL-2025-059: Denial of Service (DoS) because of null pointer dereference in 7-Zip - CVE-2025-53817
7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to version 25.0.0, a null pointer dereference in the Compound handler may lead to denial of service. Version 25.0.0 contains a fix cor the issue.
Other sources
7-Zip supports extracting from Compound Documents. Null pointer dereference in the Compound handler may lead to denial of service.
— GitHub Security Lab
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53817?
CVE-2025-53817 has a high severity rating due to the potential for denial of service through a null pointer dereference.
How do I fix CVE-2025-53817?
To fix CVE-2025-53817, upgrade to 7-Zip version 25.0.0 or later.
What versions of 7-Zip are affected by CVE-2025-53817?
CVE-2025-53817 affects all versions of 7-Zip prior to version 25.0.0.
What can happen if I don’t address CVE-2025-53817?
If not addressed, CVE-2025-53817 may lead to application crashes and denial of service for users of affected versions.
Is there a workaround for CVE-2025-53817?
There are no recommended workarounds for CVE-2025-53817; upgrading to the fixed version is necessary.