XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulti…
中危 CVSS 5.3
摘要
XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87 Patch
- https://github.com/tukaani-project/xz/releases/tag/v5.8.3 Product
- https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/03/31/13 Mailing List
- https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html
时间线
- nvd_ingest NVD