Bug 2403091

Summary: Two high-severity vulnerabilities CVE2025-11001 and CVE-2025-11002
Product: [Fedora] Fedora EPEL Reporter: Dave B <dwb7>
Component: p7zipAssignee: Davide Cavalca <davide>
Status: NEW --- QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: epel8CC: davide, dwb7, michel
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dave B 2025-10-10 14:22:41 UTC
Description of problem:
Two high-severity vulnerabilities have been discovered in the popular open-source file archiver, 7-Zip, which could allow remote attackers to execute arbitrary code.

Identified as CVE-2025-11001 and CVE-2025-11002, the flaws affect all versions of the software prior to the latest release and require immediate patching.

The developer of 7-Zip has released version 25.00, which rectifies these security flaws. All users are strongly advised to update their installations immediately to protect against potential exploitation

Version-Release number of selected component (if applicable):
p7zip-plugins-16.02-31.el8


Additional info:
https://cybersecuritynews.com/7-zip-vulnerabilities/