Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

Decoder reuse after allocation failure can cause an invalid memory write

GHSA-5qpq-xqfv-j9pg

Affected product
XZ Utils
Severity
High
Disclosed

Summary

Reusing the same liblzma stream and decoder after a dictionary allocation failure could cause an invalid write and crash when a later input reused the earlier dictionary size. The affected paths decode .lzma, .lz, and MicroLZMA; .xz decoding and raw decoder APIs are unaffected. Affects XZ Utils 5.0.0 through 5.8.3; fixed in 5.8.4. The public evidence does not establish remote code execution.

Disclosure timeline

Public disclosure

Credits

Discovered by Cantina using Apex and reported by christos-cantina-security, as credited by the XZ Utils maintainers.

References