UbuntuUpdates.org

Package "liblzma5"

Name: liblzma5

Description:

XZ-format compression library

Latest version: 5.2.5-2ubuntu1.1
Release: jammy (22.04)
Level: updates
Repository: main
Head package: xz-utils
Homepage: https://tukaani.org/xz/

Links


Download "liblzma5"


Other versions of "liblzma5" in Jammy

Repository Area Version
base main 5.2.5-2ubuntu1
security main 5.2.5-2ubuntu1.1

Changelog

Version: 5.2.5-2ubuntu1.1 2026-06-02 12:07:34 UTC

  xz-utils (5.2.5-2ubuntu1.1) jammy-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow
    - debian/patches/CVE-2026-34743.patch: adds a check to
      lzma_index_prealloc() to default to a safe size when decoding empty
      indexes in src/liblzma/common/index.c.
    - CVE-2026-34743

 -- Ian Constantin <email address hidden> Thu, 28 May 2026 19:06:40 +0300

CVE-2026-34743 XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to deco



About   -   Send Feedback to @ubuntu_updates