Echo: 7zip: security update to 22.01+really26.01+dfsg-0+deb12u1

medium Tenable Cloud Security Plugin ID 464181

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- 7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an
uninitialized heap read in the SquashFS archive handler caused by a sparsely populated index array. In the
SquashFS handler, _blockToNode is allocated with capacity for every metadata block but populated only when
an inode crosses a block boundary, so a crafted image with few inodes spanning many blocks leaves most
slots holding raw heap contents (the underlying allocator does not zero-initialize POD storage). When
OpenDir looks up an attacker-influenced blockIndex (derived from the RootInode superblock field), it reads
two of these uninitialized slots and passes them as the left/right bounds of a binary search over
_nodesPos, which dereferences the midpoint without bounds checking; if the resulting value happens to
match the search key, the returned index is used to read a full node struct from _nodes whose fields feed
further directory parsing, forming a chained OOB read primitive that is heap-layout-dependent and not
reliably triggerable. The SquashFS handler is enabled by default in stock 7z.dll and the issue triggers
during Open() with no interaction beyond opening the file; impact is denial of service from wild-pointer
dereference and potential heap information disclosure, with no write primitive. Version 26.01 fixes the
issue. (CVE-2026-48104)

Solution

Update the 7zip library and its related packages to version 22.01+really26.01+dfsg-0+deb12u1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-48104

Plugin Details

Severity: Medium

ID: 464181

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.79

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3.1

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2026-48104

CVSS v3

Risk Factor: Medium

Base Score: 4.2

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/6/2026

Vulnerability Publication Date: 6/4/2026

Reference Information

CVE: CVE-2026-48104

IAVA: 2026-A-0525