GHSL-2025-059: Denial of Service (DoS) because of null pointer dereference in 7-Zip - CVE-2025-53817
7-Zip supports extracting from Compound Documents. Null pointer dereference in the Compound handler may lead to denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2025-059?
The severity of GHSL-2025-059 is rated as 18, indicating a significant risk due to potential denial of service.
How do I fix GHSL-2025-059?
To fix GHSL-2025-059, update to the latest version of 7-Zip that includes a patch for the null pointer dereference issue.
What are the consequences of GHSL-2025-059?
The consequences of GHSL-2025-059 include crashes or service interruptions due to denial of service when handling certain Compound Documents.
Which versions of 7-Zip are affected by GHSL-2025-059?
GHSL-2025-059 affects specific versions of 7-Zip that handle Compound Documents with the identified vulnerability.
What is a null pointer dereference in the context of GHSL-2025-059?
In the context of GHSL-2025-059, a null pointer dereference occurs when the software unexpectedly tries to access memory that is not allocated, leading to a crash.