Stream Flag and Reserved Bit Vulnerability in 7-Zip Software
CVE-2022-47112

2.5LOW

Key Information:

Vendor

7-zip

Status
Vendor
CVE Published:
19 April 2025

What is CVE-2022-47112?

A vulnerability exists in 7-Zip prior to version 24.09 where the software fails to properly report errors for certain malformed xz files. This issue arises due to improper handling of stream flags and reserved bits within the xz format, potentially leading to unintended behaviors. Users may encounter corrupted files or unintended exploitation if maliciously crafted xz files are processed.

Affected Version(s)

7-Zip 22.01

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.