UbuntuUpdates.org

Package "xz-utils"

Name: xz-utils

Description:

XZ-format compression utilities

Latest version: 5.6.1+really5.4.5-1ubuntu0.2
Release: noble (24.04)
Level: security
Repository: main
Homepage: https://tukaani.org/xz/

Links


Download "xz-utils"


Other versions of "xz-utils" in Noble

Repository Area Version
base universe 5.6.1+really5.4.5-1
base main 5.6.1+really5.4.5-1
security universe 5.6.1+really5.4.5-1ubuntu0.2
updates main 5.6.1+really5.4.5-1ubuntu0.2
updates universe 5.6.1+really5.4.5-1ubuntu0.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 5.6.1+really5.4.5-1ubuntu0.2 2025-04-03 20:07:16 UTC

  xz-utils (5.6.1+really5.4.5-1ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: issue in threaded .xz decoder
    - debian/patches/CVE-2025-31115-1.patch: fix a comment in
      src/liblzma/common/stream_decoder_mt.c.
    - debian/patches/CVE-2025-31115-2.patch: simplify by removing the
      THR_STOP state in src/liblzma/common/stream_decoder_mt.c.
    - debian/patches/CVE-2025-31115-3.patch: don't free the input buffer
      too early in src/liblzma/common/stream_decoder_mt.c.
    - debian/patches/CVE-2025-31115-4.patch: don't modify thr->in_size in
      the worker thread in src/liblzma/common/stream_decoder_mt.c.
    - CVE-2025-31115

 -- Marc Deslauriers <email address hidden> Mon, 31 Mar 2025 14:22:22 -0400

CVE-2025-31115 XZ Utils provide a general-purpose data-compression library plus comma ...



About   -   Send Feedback to @ubuntu_updates