CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

DSA-6440-1 unzip - security update

unknown
Akhil Koul discovered a vulnerability in the Info-ZIP unzip program, which could result in the execution of arbitrary code if a specially crafted file is processed. https://security-tracker.debian.org/tracker/DSA-6440-1

CSIRTS triage

What
A vulnerability in unzip allows arbitrary code execution when processing a specially crafted file.
Who is affected
All users processing untrusted zip archives with affected versions of unzip.
Urgency
High; arbitrary code execution is a critical impact requiring prompt patching.
Action
Update to the patched version of unzip provided by Debian or the upstream Info-ZIP project.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch unzip

Get an email when a new unzip advisory drops — max one per day, one-click unsubscribe.

Details

Source
Debian Security Advisories (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00351.html

More from Debian Security Advisories