CVE-2025-53816Heap-based Buffer Overflow in 7-zip

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 68.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17
Latest updateOct 15

Description

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Packages4 packages

NVD7-zip/7-zip< 25.00
CVEListV5ipavlov/7-zip< 25.0.0
debiandebian/7zip-rar< 7zip-rar 25.00+ds-1 (forky)
debiandebian/p7zip-rar< 7zip-rar 25.00+ds-1 (forky)

🔴Vulnerability Details

1
OSV
CVE-2025-53816: 7-Zip is a file archiver with a high compression ratio2025-07-17

📋Vendor Advisories

2
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core (7-Zip) — CVE-2025-538162025-10-15
Debian
CVE-2025-53816: 7zip-rar - 7-Zip is a file archiver with a high compression ratio. Zeroes written outside h...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-11002 Impact, Exploitability, and Mitigation Steps | Wiz