Bug 2405273

Summary: SECURITY p7zip on EPEL8 - CVE-2023-1576
Product: [Fedora] Fedora EPEL Reporter: Dave B <dwb7>
Component: p7zipAssignee: Davide Cavalca <davide>
Status: NEW --- QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: urgent Docs Contact:
Priority: unspecified    
Version: epel8CC: davide, dwb7, michel
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dave B 2025-10-21 02:50:52 UTC
Description of problem:

For a couple of years, now, p7zip on epel8 has been at 16.02 which is subject to:
CVE-2023-1576

This needs to be patched asap.

Because p7zip doesn't maintain this old vesion, updating to the latest (v25) would be the best option since < 25.00 is also subject to, with PoC available, 
CVE-2025-11001 and CVE-2025-11002 .