Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-34743

Опубликовано: 02 апр. 2026
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 5.3

Описание

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

РелизСтатусПримечание
devel

not-affected

5.8.3-1
esm-infra-legacy/trusty

released

5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2
esm-infra-legacy/xenial

released

5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
esm-infra/bionic

released

5.2.2-1.3ubuntu0.1+esm1
esm-infra/focal

released

5.2.4-1ubuntu1.1+esm1
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

5.2.5-2ubuntu1.1
noble

released

5.6.1+really5.4.5-1ubuntu0.3
questing

released

5.8.1-1ubuntu0.1
resolute

not-affected

5.8.3-1

Показывать по

EPSS

Процентиль: 37%
0.0045
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
4 месяца назад

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

CVSS3: 5.3
nvd
4 месяца назад

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

msrc
4 месяца назад

XZ Utils: Buffer overflow in lzma_index_append()

CVSS3: 5.3
debian
4 месяца назад

XZ Utils provide a general-purpose data-compression library plus comma ...

suse-cvrf
2 месяца назад

Security update for xz

EPSS

Процентиль: 37%
0.0045
Низкий

5.3 Medium

CVSS3