Tukaani-Project Xz vulnerabilities

3 known vulnerabilities affecting tukaani-project/xz.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-34743LOWCVSS 1.7fixed in 5.8.32026-04-02
CVE-2026-34743 [LOW] CWE-122 CVE-2026-34743: XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to versio XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This is
nvd
CVE-2025-31115HIGHCVSS 8.7v>= 5.3.3alpha, < 5.8.12025-04-03
CVE-2025-31115 [HIGH] CWE-366 CVE-2025-31115: XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3 XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The effects include heap use after free and writing to an address based on the null pointer plus an offset. Applications and librari
nvd
CVE-2024-47611MEDIUMCVSS 6.3fixed in 5.6.32024-10-02
CVE-2024-47611 [MEDIUM] CWE-88 CVE-2024-47611: XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils 5.6.2 and older have a command line argument injection vulnerability. If a command line contains Unicode characters (for example, filenames) that don't exist in the current legacy
nvd