buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2025-55188
Component Overview
Vulnerability Overview
Name
CVE-2025-55188
Source
NVD (
link
)
Debian (
link
)
Description
7-Zip before 25.01 does not always properly handle symbolic links during extraction.
CWEs
CWE-59
Published Date
Aug 8, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/ip7z/7zip/compare/25.00...25.01
Product
https://github.com/ip7z/7zip/releases/tag/25.01
Release Notes
https://github.com/lunbun/CVE-2025-55188/
Exploit
https://lunbun.dev/blog/cve-2025-55188/
Exploit
https://sourceforge.net/p/sevenzip/discussion/45797/thread/da14cd780b/
Product
https://www.openwall.com/lists/oss-security/2025/08/09/1
Mailing List
https://youtu.be/sWT6M1cfnwM
Exploit
Analysis
#
Affected Component
Analysis
p7zip
Exploitable
Vulnerability Ratings
#
3.6
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
p7zip
buildroot
master
17.06
Exploitable
p7zip
yocto
kirkstone
16.02
Exploitable
p7zip
yocto
scarthgap
16.02
Exploitable