UbuntuUpdates.org

Package "liblzma5"

Name: liblzma5

Description:

XZ-format compression library

Latest version: 5.8.1-1ubuntu0.1
Release: questing (25.10)
Level: security
Repository: main
Head package: xz-utils
Homepage: https://tukaani.org/xz/

Links


Download "liblzma5"


Other versions of "liblzma5" in Questing

Repository Area Version
base main 5.8.1-1build2
updates main 5.8.1-1ubuntu0.1

Changelog

Version: 5.8.1-1ubuntu0.1 2026-06-02 10:08:03 UTC

  xz-utils (5.8.1-1ubuntu0.1) questing-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow
    - debian/patches/CVE-2026-34743.patch: adds a check to
      lzma_index_prealloc() to default to a safe size when decoding empty
      indexes in src/liblzma/common/index.c.
    - CVE-2026-34743

 -- Ian Constantin <email address hidden> Thu, 28 May 2026 19:06:53 +0300

CVE-2026-34743 XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to deco



About   -   Send Feedback to @ubuntu_updates