Logo
vulnerabilityCVE-2026-34743
Name
CVE-2026-34743
Source
NVD ( link)Debian ( link)
Description
XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
xz
Patched

Vulnerability Ratings#


1.7
CVSSv4
5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
5.8.3
Not Affected
openwrt
master
5.8.3-r1
Not Affected
openwrt
openwrt-25.12
5.8.1-r1
Exploitable
yocto
kirkstone
5.2.6
Exploitable
yocto
master
5.8.3
Not Affected
yocto
scarthgap
5.4.7
Patched

Resolved with patches#


xz (buildroot:2025.02.x)

#
Title
Author
Resolve
1
liblzma: Fix a buffer overflow in lzma_index_append()
Lasse Collin <lasse.collin@tukaani.org>
CVE-2026-34743

xz (yocto:scarthgap)

#
Title
Author
Resolve
1
liblzma: Fix a buffer overflow in lzma_index_append()
Lasse Collin <lasse.collin@tukaani.org>
CVE-2026-34743