CVE-2026-34743: XZ Utils: Buffer overflow in lzma_index_append()
Last updated 2 June 2026
Other sources
XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzmaindexdecoder() was used to decode an Index that contained no Records, the resulting lzmaindex was left in a state where where a subsequent lzmaindexappend() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.
— MITRE
XZ Utils: Buffer overflow in lzmaindexappend()
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xz-utilsto a version that resolves this vulnerability.Fixed in 5.8.3-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.4.4-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.2.5-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.90.0-7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.75.0-28 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.72.0-16 - Upgrade
Upgrade
XZ Utilsto a version that resolves this vulnerability.Fixed in 5.8.3