CVE-2018-5996: 7-Zip

High severity, CVSS 7.8. EPSS: 2.9% chance of exploitation in the next 30 days.

Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.

Affected products

  • 7-Zip 7-Zip: before 18.00 (fixed in 18.00)
  • 7-Zip p7zip: before 18.0 (fixed in 18.0)
  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only

Published 2018-01-31. Last modified 2026-06-17.