CVE-2026-34743

Published: April 4, 2026Last modified: May 4, 2026

Description

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

Severity score breakdown

ParameterValue
Base score5.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSxzFixed (5.2.9_p525-r1)
25 LTSxzFixed (5.8.3-r0)
StreamxzFixed (5.8.3-r0)
Hardened Containers23 LTSxzFixed (5.2.9_p525-r1)
25 LTSxzFixed (5.8.3-r0)
StreamxzFixed (5.8.3-r0)

References

ON THIS PAGE