Echo: 7zip: security update to 22.01+really26.01+dfsg-0+deb12u1

medium Tenable Self-Hosted Container Security Plugin ID 457466

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- 7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An
uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCapsule
function allocates a heap buffer of attacker-declared CapsuleImageSize (up to 1 GiB) without zero-
initialization, then reads the file contents into it with ReadStream_FALSE whose return value is silently
discarded. If the file is truncated, the unread tail of the buffer retains uninitialized heap memory,
which is then exposed as extracted file content via GetStream. Version 26.0.1 fixes the issue.
(CVE-2026-48101)

Solution

Update the 7zip library and its related packages to version 22.01+really26.01+dfsg-0+deb12u1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-48101

Plugin Details

Severity: Medium

ID: 457466

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.71

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-48101

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/6/2026

Vulnerability Publication Date: 6/4/2026

Reference Information

CVE: CVE-2026-48101

IAVA: 2026-A-0525