https://seclists.org/oss-sec/2025/q2/11: XZ Utils: Thaded decoder fes memory too early (CVE-2025-31115)
Published Apr 3, 2025
·Updated
Affected Software
1 affected component
XZ Utils liblzma>=5.3.3alpha<=5.8.0
Frequently Asked Questions
1
What is the severity of CVE-2025-31115?
CVE-2025-31115 has been assessed as a denial of service vulnerability due to the potential for crashing applications.
2
How do I fix CVE-2025-31115?
To fix CVE-2025-31115, you should update to the latest version of XZ Utils that contains the patch for this vulnerability.
3
What can be exploited in CVE-2025-31115?
CVE-2025-31115 can be exploited to cause a crash or denial of service through heap use after free and writing to a null pointer.
4
Which software is affected by CVE-2025-31115?
CVE-2025-31115 affects XZ Utils, specifically the threaded decoder in liblzma.
5
Is CVE-2025-31115 related to memory management issues?
Yes, CVE-2025-31115 is related to memory management issues that can lead to heap corruption and null pointer dereference.