HomeSecurityNew vulnerability in 7-Zip allows system corruption

New vulnerability in 7-Zip allows system corruption

A critical memory corruption vulnerability has been identified in the popular compressed file manager 7-Zip, which allows attackers to cause denial of service (DoS) conditions via specially crafted RAR5 files.

See also: BIND 9 vulnerabilities expose organizations to DoS attacks

7‑Zip vulnerability

The vulnerability, with identifier CVE-2025-53816 and code GHSL-2025-058, affects all versions of 7-Zip prior to version 25.00.

Security researcher Jaroslav Lobačevski from GitHub Security Lab discovered the vulnerability, which has a CVSS score of 5.5, ranking it as medium severity. While the vulnerability is unlikely to allow arbitrary code execution, it poses significant risks for denial of service attacks on systems that process untrusted compressed files.

The vulnerability results from a heap-based buffer overflow in the implementation of 7-Zip's RAR5 decoder. Specifically, the bug is located in the NCompress::NRar5::CDecoder, when the software attempts to recover corrupted data from a file by padding the corrupted sections with zeros.

The root cause of the vulnerability is an incorrect calculation of the rem value during the memory zeroing process. When processing RAR5 files, the decoder calls the function My_ZeroMemory(_window + _winPos, (size_t)rem) where the rem parameter is calculated as _lzEnd – lzSize .

See also: VMware fixed vulnerabilities used at Pwn2Own Berlin 2025

However, the _lzEnd depends on the size of previous elements in the file, which can be controlled by the attacker. This miscalculation allows writing zero values ​​beyond the bounds of the allocated buffer on the heap, potentially corrupting adjacent memory areas and causing the application.

New vulnerability in 7-Zip allows system corruption
New vulnerability in 7-Zip allows system corruption

Tests using AddressSanitizer (ASAN) have shown that specially crafted RAR5 files can cause heap-based buffer overflows, with one proof-of-concept writing 9,469 bytes beyond the allocated buffer.

7-Zip is one of the most widely used tools worldwide, with the official website receiving over 1.3 million visits per month and the software having been downloaded millions of times through various distribution channels.

The popularity of the software in both personal and business environments significantly increases the potential impact of this vulnerability.

See also: Google fixes critical zero-day vulnerability in Chrome

What makes this vulnerability particularly concerning is the fact that 7-Zip is widely used by both consumers and businesses, meaning an attacker could target a wide range of systems with a relatively simple technique. Furthermore, the nature of the vulnerability — heap overflow — could cause serious disruptions, such as data loss or service interruption, creating reliability and security issues. Therefore, it is critical to promptly apply patches and inform users to mitigate the risks.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS