216.73.217.22

CVE-2025-31115

· Published 03/04/2025 17:15 · Modified 03/04/2025 20:15

Labels: CVE-2025-31115 2025-04-03CVE-2025-31115CWE-366[email protected]

Essential information

Published
03/04/2025 17:15
Modified
03/04/2025 20:15
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The effects include heap use after free and writing to an address based on the null pointer plus an offset. Applications and libraries that use the lzma_stream_decoder_mt function are affected. The bug has been fixed in XZ Utils 5.8.1, and the fix has been committed to the v5.4, v5.6, v5.8, and master branches in the xz Git repository. No new release packages will be made from the old stable branches, but a standalone patch is available that applies to all affected releases.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tukaani / xz cpe:2.3:a:tukaani:xz:5.3.3alpha-5.8.0:*:*:*:*:*:*:*

References