26.02: XZ decompression buffer overflow fixed
Catalog row in Vendor License Evidence · Cited
- Kind
- Documentation excerpt
- Excerpt
- "CVE-2026-14266 : XZ Decompression Heap-based Buffer Overflow Remote Code Execution."
- Locator
- history.txt, 26.02 (2026-06-25)
- Applies to
- Security fixes ship only in new 7-Zip releases; 26.02 and 26.03 fixed CVE-listed vulnerabilities
- Supports rules
- Related programs