https://reddit.com/r/cybersecurity/comments/1jtfelt/xz_utils_again/: XZ utils.. again
Published Apr 7, 2025
·Updated
Affected Software
1 affected component
XZ Utils XZ Utils>=5.3.3alpha<5.8.0
Frequently Asked Questions
1
What is the severity of CVE-2025-31115?
CVE-2025-31115 has a CVSSv4 score of 8.7, indicating high severity.
2
What vulnerability does CVE-2025-31115 describe?
CVE-2025-31115 describes a heap use-after-free bug in the multithreaded decoder of XZ Utils.
3
How do I fix CVE-2025-31115?
To fix CVE-2025-31115, upgrade XZ Utils to version 5.8.1 or later.
4
What versions of XZ Utils are affected by CVE-2025-31115?
CVE-2025-31115 affects XZ Utils versions 5.3.3alpha to 5.8.0.
5
What impact can CVE-2025-31115 have on a system?
CVE-2025-31115 can cause crashes or memory corruption in affected systems.