| Name | CVE-2026-34743 |
| Description | XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-4690-1 |
| Debian Bugs | 1132497 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| xz-utils (PTS) | bookworm | 5.4.1-1+deb12u1 | fixed |
| bookworm (security) | 5.4.1-1+deb12u2 | fixed | |
| trixie | 5.8.1-1+deb13u1 | fixed | |
| trixie (security) | 5.8.1-1+deb13u2 | fixed | |
| forky, sid | 5.8.4-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| xz-utils | source | bullseye | 5.2.5-2.1~deb11u2 | DLA-4690-1 | ||
| xz-utils | source | bookworm | 5.4.1-1+deb12u1 | |||
| xz-utils | source | trixie | 5.8.1-1+deb13u1 | |||
| xz-utils | source | (unstable) | 5.8.3-1 | 1132497 |
https://tukaani.org/xz/index-append-overflow.html
Fixed by: https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87 (v5.8.3)
Test case: https://github.com/tukaani-project/xz/commit/a3ea8832bec11128597c454f5d14d05ef6010e3f (v5.8.3)
Test note: https://github.com/tukaani-project/xz/commit/f3b5688159c60495f48db3942a36509671dfce89 (v5.8.4)