New Debian xz-utils 5.4.1-1 fixes: This update addresses the following issue: * xz: XZ has a heap-use-after-free bug in threaded .xz decoder (CVE-2025-31115)
--- mirror/ftp/pool/main/x/xz-utils/xz-utils_5.4.1-0.2.dsc +++ apt/ucs_5.2-0-errata5.2-1/source/xz-utils_5.4.1-1.dsc @@ -1,3 +1,8 @@ +5.4.1-1 [Thu, 03 Apr 2025 21:55:39 +0200] Sebastian Andrzej Siewior <sebastian@breakpoint.cc>: + + * Add fix from upstream when the threaded decompresses frees memory too + early on invalid input (CVE-2025-31115). + 5.4.1-0.2 [Sun, 12 Feb 2023 21:22:50 +0100] Sebastian Andrzej Siewior <sebastian@breakpoint.cc>: * Non-maintainer upload. <http://piuparts.knut.univention.de/5.2-1/#8604445535375945612>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-1] 05877057278 Bug #58168: xz-utils 5.4.1-1 doc/errata/staging/xz-utils.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x66>