Logo
vulnerabilityCVE-2025-31115
Name
CVE-2025-31115
Source
NVD ( link)Debian ( link)
Description
XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The effects include heap use after free and writing to an address based on the null pointer plus an offset. Applications and libraries that use the lzma_stream_decoder_mt function are affected. The bug has been fixed in XZ Utils 5.8.1, and the fix has been committed to the v5.4, v5.6, v5.8, and master branches in the xz Git repository. No new release packages will be made from the old stable branches, but a standalone patch is available that applies to all affected releases.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
xz
Patched

Vulnerability Ratings#


8.7
CVSSv4
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
5.6.4
Patched
buildroot
master
5.8.3
Not Affected
openwrt
master
5.8.3-r1
Not Affected
openwrt
openwrt-25.12
5.8.1-r1
Not Affected
yocto
kirkstone
5.2.6
Not Affected
yocto
master
5.8.3
Not Affected

Resolved with patches#


xz (buildroot:2025.02.x)

#
Title
Author
Resolve
1
liblzma: mt dec: Fix a comment
Lasse Collin <lasse.collin@tukaani.org>
CVE-2025-31115
2
liblzma: mt dec: Simplify by removing the THR_STOP state
Lasse Collin <lasse.collin@tukaani.org>
CVE-2025-31115
3
liblzma: mt dec: Don't free the input buffer too early
Lasse Collin <lasse.collin@tukaani.org>
CVE-2025-31115
4
liblzma: mt dec: Don't modify thr->in_size in the worker
Lasse Collin <lasse.collin@tukaani.org>
CVE-2025-31115

xz (yocto:scarthgap)

#
Title
Author
Resolve
1
liblzma: mt dec: Fix a comment
Lasse Collin <lasse.collin@tukaani.org>
CVE-2025-31115
2
liblzma: mt dec: Don't modify thr->in_size in the worker
Lasse Collin <lasse.collin@tukaani.org>
CVE-2025-31115
3
liblzma: mt dec: Don't free the input buffer too early
Lasse Collin <lasse.collin@tukaani.org>
CVE-2025-31115
4
liblzma: mt dec: Simplify by removing the THR_STOP state
Lasse Collin <lasse.collin@tukaani.org>
CVE-2025-31115