XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tukaani-project
Tukaani-project xz |
|
| Vendors & Products |
Tukaani-project
Tukaani-project xz |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3. | |
| Title | XZ Utils: Buffer overflow in lzma_index_append() | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-04-02T18:36:37.450Z
Updated: 2026-04-03T12:59:06.096Z
Reserved: 2026-03-30T19:17:10.224Z
Link: CVE-2026-34743
No data.
Status : Received
Published: 2026-04-02T19:21:33.187
Modified: 2026-04-02T20:16:24.650
Link: CVE-2026-34743
No data.