https://seclists.org/oss-sec/2025/q2/10: XZ Utils: Thaded decoder fes memory too early (CVE-2025-31115)
Published Apr 3, 2025
·Updated
Affected Software
1 affected component
XZ Utils liblzma>=5.3.3alpha<=5.8.0
Frequently Asked Questions
1
What is the severity of CVE-2025-31115?
CVE-2025-31115 is classified as a denial of service vulnerability stemming from a flaw in the threaded .xz decoder.
2
How do I fix CVE-2025-31115?
To fix CVE-2025-31115, upgrade to the latest version of XZ Utils that addresses this vulnerability.
3
Which versions of XZ Utils are affected by CVE-2025-31115?
CVE-2025-31115 affects XZ Utils versions from 5.3.3a up to the fixed version.
4
What type of issue does CVE-2025-31115 cause?
CVE-2025-31115 can cause a crash due to heap use after free and writing to a null pointer.
5
Who reported CVE-2025-31115?
CVE-2025-31115 was reported by Sam James from Gentoo.