{"id":"ECHO-c41c-0d0a-92ad","upstream":["CVE-2022-47112"],"severity":[],"modified":"2026-07-19T16:41:19.923Z","affected":[{"package":{"ecosystem":"Echo","name":"7zip"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.01+dfsg-1~deb13u2"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2022-47112"}],"withdrawn":"2026-07-19T16:41:19.923Z","summary":"Low-severity (CVSS 3.1 2.5, CWE-754, Debian \"unimportant\") error-reporting\nquirk: 7-Zip 22.01 silently returns OK for an xz file with reserved bits\nset in the stream flags instead of flagging it. No memory-safety impact.\nNVD's affected-version data is pinned to exactly 22.01 and states \"Some\nlater versions are unaffected\"; remediated upstream by version currency,\nnot by a separate patch, so there is nothing to backport. Verified against\nthe reporter's PoC (boofish/semantic-bugs pocs/poc2.xz) on this build's\n25.01 binaries: the standalone 7za/7zr hard-error (exit 2, \"Is not\narchive\") and 7zz/7z no longer silently accept it (now emit \"Warnings: 1\"),\nso the reported silent-acceptance behavior does not reproduce.\n"}