Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34743

Опубликовано: 02 апр. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

A flaw was found in XZ Utils. When the lzma_index_decoder() function processes an empty index, and a subsequent lzma_index_append() operation is performed, insufficient memory is allocated. This can lead to a buffer overflow, potentially causing a denial of service (DoS) for affected systems.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xzOut of support scope
Red Hat Enterprise Linux 7xzFix deferred
Red Hat Enterprise Linux 8xzFix deferred
Red Hat Enterprise Linux 9xzAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred
Red Hat Enterprise Linux 10xzFixedRHSA-2026:6478708.09.2026
Red Hat Hardened Imagesxz-main-5.8.3-1.1.hum1FixedRHSA-2026:764711.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2454589xz: XZ Utils: Denial of Service via buffer overflow in index decoding

EPSS

Процентиль: 38%
0.0045
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
6 месяцев назад

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

CVSS3: 5.3
nvd
6 месяцев назад

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

CVSS3: 5.3
msrc
6 месяцев назад

XZ Utils: Buffer overflow in lzma_index_append()

CVSS3: 5.3
debian
6 месяцев назад

XZ Utils provide a general-purpose data-compression library plus comma ...

suse-cvrf
4 месяца назад

Security update for xz

EPSS

Процентиль: 38%
0.0045
Низкий

5.3 Medium

CVSS3