UbuntuUpdates.org

Package "liblzma-dev"

Name: liblzma-dev

Description:

XZ-format compression library - development files

Latest version: 5.6.1+really5.4.5-1ubuntu0.3
Release: noble (24.04)
Level: security
Repository: main
Head package: xz-utils
Homepage: https://tukaani.org/xz/

Links


Download "liblzma-dev"


Other versions of "liblzma-dev" in Noble

Repository Area Version
base main 5.6.1+really5.4.5-1
updates main 5.6.1+really5.4.5-1ubuntu0.2

Changelog

Version: 5.6.1+really5.4.5-1ubuntu0.3 2026-06-02 10:07:47 UTC

  xz-utils (5.6.1+really5.4.5-1ubuntu0.3) noble-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow
    - debian/patches/CVE-2026-34743.patch: adds a check to
      lzma_index_prealloc() to default to a safe size when decoding empty
      indexes in src/liblzma/common/index.c.
    - CVE-2026-34743

 -- Ian Constantin <email address hidden> Thu, 28 May 2026 19:06:47 +0300

Source diff to previous version
CVE-2026-34743 XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to deco

Version: 5.6.1+really5.4.5-1ubuntu0.2 2025-04-03 20:07:16 UTC

  xz-utils (5.6.1+really5.4.5-1ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: issue in threaded .xz decoder
    - debian/patches/CVE-2025-31115-1.patch: fix a comment in
      src/liblzma/common/stream_decoder_mt.c.
    - debian/patches/CVE-2025-31115-2.patch: simplify by removing the
      THR_STOP state in src/liblzma/common/stream_decoder_mt.c.
    - debian/patches/CVE-2025-31115-3.patch: don't free the input buffer
      too early in src/liblzma/common/stream_decoder_mt.c.
    - debian/patches/CVE-2025-31115-4.patch: don't modify thr->in_size in
      the worker thread in src/liblzma/common/stream_decoder_mt.c.
    - CVE-2025-31115

 -- Marc Deslauriers <email address hidden> Mon, 31 Mar 2025 14:22:22 -0400

CVE-2025-31115 XZ Utils provide a general-purpose data-compression library plus comma ...



About   -   Send Feedback to @ubuntu_updates