CVE-2026-58052

Publication date 28 June 2026

Last updated 29 June 2026


Ubuntu priority

Cvss 3 Severity Score

3.3 · Low

Score breakdown

Description

7-Zip for Windows through 26.02 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zone.Identifier:$DATA' is not matched and NTFS canonicalizes it to the same stream, overwriting the propagated Internet-zone marker with ZoneId=0. A second STM record named '::$DATA' overwrites the extracted file's default data stream, letting an attacker defeat SmartScreen/MotW warnings and spoof file content.

Read the notes from the security team

Status

Package Ubuntu Release Status
7zip 26.04 LTS resolute
Not affected
25.10 questing
Not affected
24.04 LTS noble
Not affected
22.04 LTS jammy
Not affected

Notes


rodrigo-zaiden

only affects Windows

Severity score breakdown

CVSS version:

Base score 4.8 · Medium

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Base score 3.3 · Low

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N


Access our resources on patching vulnerabilities