Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34743

Опубликовано: 02 апр. 2026
Источник: redhat
CVSS3: 5.3

Описание

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

A flaw was found in XZ Utils. When the lzma_index_decoder() function processes an empty index, and a subsequent lzma_index_append() operation is performed, insufficient memory is allocated. This can lead to a buffer overflow, potentially causing a denial of service (DoS) for affected systems.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10xzAffected
Red Hat Enterprise Linux 6xzOut of support scope
Red Hat Enterprise Linux 7xzFix deferred
Red Hat Enterprise Linux 8xzFix deferred
Red Hat Enterprise Linux 9xzFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesxz-main-5.8.3-1.1.hum1FixedRHSA-2026:764711.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2454589xz: XZ Utils: Denial of Service via buffer overflow in index decoding

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

CVSS3: 5.3
nvd
4 месяца назад

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

msrc
4 месяца назад

XZ Utils: Buffer overflow in lzma_index_append()

CVSS3: 5.3
debian
4 месяца назад

XZ Utils provide a general-purpose data-compression library plus comma ...

suse-cvrf
2 месяца назад

Security update for xz

5.3 Medium

CVSS3