Memory Corruption Vulnerability in 7-Zip by RAR5 Handler
CVE-2025-53816

5.5MEDIUM

Key Information:

Vendor

Ipavlov

Status
Vendor
CVE Published:
17 July 2025

What is CVE-2025-53816?

7-Zip, a widely used file archiver known for its efficient compression capabilities, has a vulnerability in its RAR5 handler. In affected versions prior to 25.0.0, the software improperly manages memory by writing zero values outside the designated heap buffer. This flaw could lead to memory corruption, which may result in unexpected behavior or denial of service. Users are strongly encouraged to upgrade to version 25.0.0 or later, where this issue has been addressed, to ensure the security and stability of their file archiving processes.

Affected Version(s)

7-Zip < 25.0.0

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.