Summary
Reusing the same liblzma stream and decoder after a dictionary allocation failure could cause an invalid write and crash when a later input reused the earlier dictionary size. The affected paths decode .lzma, .lz, and MicroLZMA; .xz decoding and raw decoder APIs are unaffected. Affects XZ Utils 5.0.0 through 5.8.3; fixed in 5.8.4. The public evidence does not establish remote code execution.
Disclosure timeline
- Public disclosure
Credits
Discovered by Cantina using Apex and reported by christos-cantina-security, as credited by the XZ Utils maintainers.