CVE-2022-47112 Details
Description
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.
A vulnerability exists in 7-Zip version 22.01, where the application fails to report errors for certain invalid XZ files related to stream flags and reserved bits. This issue can lead to unexpected behavior, as 7-Zip incorrectly indicates successful processing of corrupted files. In contrast, some later versions of 7-Zip do not exhibit this problem.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/boofish/semantic-bugs/ | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| 7-zip 7-zip | 22.01 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 18, 2025 | Initial Analysis | [email protected] |
| Apr 19, 2025 | CVE Modified | [email protected] |
| Apr 19, 2025 | New CVE Received | [email protected] |