The LGPL makes it perfectly legal for the closed-source antivirus component to not load any 7zip .so binary that is not signed by the antivirus vendor, of a known hash, or so on... and the code loading said shared-object need not be available or modifiable, just the code for the vulnerable .so they do ship.
Specifically, if forcing to sign a package with a different key (making it a different package) for private purposes is enough, or if the redistribution rights of the whole is required. Finally, if you cannot replace the software because of code signing and no public debug mode, that seems incompatible too...
7-zip is licensed under LGPLv2.1. "do not restrict" is not a string that appears in v2.1 The entire second part you quoted was added in version 3.
However, F-Secure applies several patches to harden 7-Zip and to fix bugs that are not yet fixed in the public 7-Zip version. So it is not clear whether it is always such a good idea to do this.