Stream Flag and Reserved Bit Vulnerability in 7-Zip Software
CVE-2022-47112

3.3LOW

Key Information:

Vendor

7-zip

Status
Vendor
CVE Published:
19 April 2025

What is CVE-2022-47112?

A vulnerability exists in 7-Zip prior to version 24.09 where the software fails to properly report errors for certain malformed xz files. This issue arises due to improper handling of stream flags and reserved bits within the xz format, potentially leading to unintended behaviors. Users may encounter corrupted files or unintended exploitation if maliciously crafted xz files are processed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

7-Zip 22.01

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.