7-Zip Block Flags and Reserved Bits Error Handling Vulnerability

Vulnerability

A vulnerability exists in 7-Zip version 22.01, where the application fails to report errors for certain invalid xz files related to block flags and reserved bits. This issue allows for the creation of malicious compressed xz files that 7-Zip incorrectly processes as valid, potentially leading to unexpected behaviors in programs that rely on 7-Zip for file handling.

Impact

Exploitation of this vulnerability can cause 7-Zip to incorrectly process corrupted xz files, returning a success status while ignoring the actual error. This could lead to critical tasks failing when they depend on the improperly handled components.

Reproduction

The vulnerability can be reproduced by using 7-Zip to extract a corrupted xz file that has been crafted to exploit this issue. The xz utility will correctly identify the file as broken, but 7-Zip will fail to report the error, demonstrating the vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
6.0
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.