RHSA-2025:7524: Important: xz security update
Important: xz security update
Other sources
XZ Utils is an integrated collection of user-space file compression utilities based on the Lempel-Ziv-Markov chain algorithm (LZMA), which performs lossless data compression. The algorithm provides a high compression ratio while keeping the decompression time short.Security Fix(es): xz: XZ has a heap-use-after-free bug in threaded .xz decoder (CVE-2025-31115) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:7524?
RHSA-2025:7524 is classified as an important security update.
What does RHSA-2025:7524 address?
RHSA-2025:7524 addresses vulnerabilities in the xz compression utilities.
How do I fix RHSA-2025:7524?
To fix RHSA-2025:7524, update to xz version 5.6.2-4.el10_0 or newer.
What are the affected packages in RHSA-2025:7524?
Affected packages in RHSA-2025:7524 include xz, xz-devel, and xz-libs, among others.
Is RHSA-2025:7524 applicable to all Red Hat systems?
RHSA-2025:7524 is specifically applicable to Red Hat Enterprise Linux systems, including various architectures like x86_64 and IBM z Systems.