Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-31115

Опубликовано: 03 апр. 2025
Источник: ubuntu
Приоритет: medium

Описание

XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The effects include heap use after free and writing to an address based on the null pointer plus an offset. Applications and libraries that use the lzma_stream_decoder_mt function are affected. The bug has been fixed in XZ Utils 5.8.1, and the fix has been committed to the v5.4, v5.6, v5.8, and master branches in the xz Git repository. No new release packages will be made from the old stable branches, but a standalone patch is available that applies to all affected releases.

РелизСтатусПримечание
devel

released

5.6.4-1ubuntu1
esm-infra-legacy/trusty

not-affected

esm-infra/bionic

not-affected

esm-infra/focal

not-affected

5.2.4-1ubuntu1.1
esm-infra/xenial

not-affected

focal

not-affected

5.2.4-1ubuntu1.1
jammy

not-affected

5.2.5-2ubuntu1
noble

released

5.6.1+really5.4.5-1ubuntu0.2
oracular

released

5.6.2-2ubuntu0.2
plucky

released

5.6.4-1ubuntu1

Показывать по

Связанные уязвимости

CVSS3: 7.5
redhat
3 месяца назад

XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The effects include heap use after free and writing to an address based on the null pointer plus an offset. Applications and libraries that use the lzma_stream_decoder_mt function are affected. The bug has been fixed in XZ Utils 5.8.1, and the fix has been committed to the v5.4, v5.6, v5.8, and master branches in the xz Git repository. No new release packages will be made from the old stable branches, but a standalone patch is available that applies to all affected releases.

nvd
3 месяца назад

XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The effects include heap use after free and writing to an address based on the null pointer plus an offset. Applications and libraries that use the lzma_stream_decoder_mt function are affected. The bug has been fixed in XZ Utils 5.8.1, and the fix has been committed to the v5.4, v5.6, v5.8, and master branches in the xz Git repository. No new release packages will be made from the old stable branches, but a standalone patch is available that applies to all affected releases.

msrc
2 месяца назад

Описание отсутствует

debian
3 месяца назад

XZ Utils provide a general-purpose data-compression library plus comma ...

suse-cvrf
3 месяца назад

Security update for xz