AVG-2861 log

Package lib32-xz
Status Fixed
Severity Medium
Type denial of service
Affected 5.8.0-1
Fixed 5.8.1-1
Current 5.8.1-1 [multilib]
Ticket None
Created Thu Apr 3 17:13:14 2025
Advisory Pending
Issue Severity Remote Type Description
CVE-2025-31115 Medium No Denial of service
In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The effects include...
References
https://tukaani.org/xz/threaded-decoder-early-free.html