UbuntuUpdates.org

Package "xzdec"

Name: xzdec

Description:

XZ-format compression utilities - tiny decompressors

Latest version: 5.6.1+really5.4.5-1ubuntu0.2
Release: noble (24.04)
Level: security
Repository: universe
Head package: xz-utils
Homepage: https://tukaani.org/xz/

Links


Download "xzdec"


Other versions of "xzdec" in Noble

Repository Area Version
base universe 5.6.1+really5.4.5-1
updates universe 5.6.1+really5.4.5-1ubuntu0.2

Changelog

Version: 5.6.1+really5.4.5-1ubuntu0.2 2025-04-03 20:07:21 UTC

  xz-utils (5.6.1+really5.4.5-1ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: issue in threaded .xz decoder
    - debian/patches/CVE-2025-31115-1.patch: fix a comment in
      src/liblzma/common/stream_decoder_mt.c.
    - debian/patches/CVE-2025-31115-2.patch: simplify by removing the
      THR_STOP state in src/liblzma/common/stream_decoder_mt.c.
    - debian/patches/CVE-2025-31115-3.patch: don't free the input buffer
      too early in src/liblzma/common/stream_decoder_mt.c.
    - debian/patches/CVE-2025-31115-4.patch: don't modify thr->in_size in
      the worker thread in src/liblzma/common/stream_decoder_mt.c.
    - CVE-2025-31115

 -- Marc Deslauriers <email address hidden> Mon, 31 Mar 2025 14:22:22 -0400

CVE-2025-31115 XZ Utils provide a general-purpose data-compression library plus comma ...



About   -   Send Feedback to @ubuntu_updates