7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of streams. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-24307.
Conclusion & alert: CVE-2024-11612 is rated Moderate Risk (55/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.75%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-11 | 1.80% | 1.75% | -0.05% |
| 2 | 2026-05-27 | 0.47% | 1.80% | +1.32% |
| 3 | 2026-05-12 | — | 0.47% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.0 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2024-11612 unimportant priority: Debian including 2 source packages (7zip, p7zip), 7 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 7. | https://security-tracker.debian.org/tracker/CVE-2024-11612 |
suse
|
medium | CVE-2024-11612 severity moderate: SUSE including 1 source package names (7zip), 2 product×package rows across 2 product lines (SUSE Linux Enterprise Server 16.0, SUSE Linux Enterprise Server for SAP applications 16.0): Known Not Affected 2. | https://www.suse.com/security/cve/CVE-2024-11612/ |
ubuntu
|
medium | CVE-2024-11612 medium priority: Ubuntu including 2 source packages (7zip, p7zip), 17 status rows across 10 suites (bionic, focal, jammy, noble, oracular, plucky, questing, trusty, upstream, xenial): deferred 7, not-affected 7, released 2, DNE 1. | https://ubuntu.com/security/CVE-2024-11612 |
| URL | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-1606/ | Third Party Advisory |