XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 04 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


Fri, 03 Apr 2026 14:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Tukaani-project
Tukaani-project xz
Vendors & Products Tukaani-project
Tukaani-project xz

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.
Title XZ Utils: Buffer overflow in lzma_index_append()
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 1.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-04-03T12:59:06.096Z

Reserved: 2026-03-30T19:17:10.224Z

Link: CVE-2026-34743

cve-icon Vulnrichment

Updated: 2026-04-02T19:24:10.537Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-02T19:21:33.187

Modified: 2026-04-03T16:10:23.730

Link: CVE-2026-34743

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-02T18:36:37Z

Links: CVE-2026-34743 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-03T09:16:39Z

Weaknesses