Bug 2381832
| Summary: | CVE-2025-53817 advancecomp: 7-Zip Null pointer array write [fedora-42] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Jon Moroney <jmoroney> |
| Component: | advancecomp | Assignee: | Ben Beasley <code> |
| Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 42 | CC: | code, i, tdawson |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["95281dee-99fa-439e-8987-34613745b5ca"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2025-07-19 12:30:24 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2381769 | ||
|
Description
Jon Moroney
2025-07-17 22:09:41 UTC
According to https://www.cve.org/CVERecord?id=CVE-2025-53817, the CVE arises from a defect in NArchive::NCom::CHandler::GetStream; https://securitylab.github.com/advisories/GHSL-2025-059_7-Zip/ provides further details. The 7-Zip code bundled and forked in advancecomp does not contain an NCom handler, and no code resembling the context around the bug in the GitHub advisory could be found. It is therefore reasonable to presume that advancecomp is not affected by this particular CVE. |