CVE-2023-31102: 7-Zip

High severity, CVSS 7.8. EPSS: 57.1% chance of exploitation in the next 30 days.

Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

Affected products

  • 7-Zip 7-Zip: before 22.01 (fixed in 22.01)
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified

Published 2023-11-03. Last modified 2026-06-17.