Known vulnerabilities in xz (Red Hat package)
Vendor:
Red Hat Inc.
Software:
xz (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:xz_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU106970 - Heap-based Buffer Overflow CVE-2025-31115 |
CWE-122 | High | 5.6.2-4.el10_0 | 03.04.2025 |
SB20250403127 SB20250403129 SB20250403137 and 18 more |
||
| #VU62002 - Improper input validation CVE-2022-1271 |
CWE-20 | High | 5.2.2-2.el7_9, 5.2.4-4.el8_1, 5.2.4-4.el8_2, 5.2.4-4.el8_4, 5.2.4-4.el8_6, 5.2.5-8.el9_0 | 08.04.2022 |
SB2022040803 SB2022040804 SB2022040822 and 134 more |