Heap-based buffer overflow in XZ Utils - CVE-2025-31115

 

Heap-based buffer overflow in XZ Utils - CVE-2025-31115

Published: April 3, 2025


Vulnerability identifier: #VU106970
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31115
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the lzma_stream_decoder_mt() function. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

XZ Utils
Debian Linux
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
FreeBSD
Basesystem Module
openSUSE Leap
Anolis OS
openEuler
Ubuntu
Fedora
IBM Observability with Instana
APEX Cloud Platform for Red Hat OpenShift
Storage Defender - Resiliency Service
APEX Cloud Platform for Microsoft Azure
SmartFabric Manager
perl-Compress-Raw-Lzma
xz-utils (Debian package)
xz
liblzma5-64bit
xz-devel-64bit
liblzma5-64bit-debuginfo
xz-lang
liblzma5
liblzma5-debuginfo
xz-debuginfo
xz-debugsource
xz-devel
xz-static-devel
liblzma5-32bit-debuginfo
liblzma5-32bit
xz-devel-32bit
xz-static
xz-lzma-compat
xz-libs
xz-help
xz-utils (Ubuntu package)
xz (Red Hat package)
app-arch/xz-utils

How to mitigate CVE-2025-31115

Install updates from vendor's website.

XZ Utils - update to 5.8.1
IBM Observability with Instana - update to 1.0.297
Storage Defender - Resiliency Service - update to 2.0.14
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
perl-Compress-Raw-Lzma - addressed in versions 2.209-9.fc40, 2.212-6.fc41
APEX Cloud Platform for Red Hat OpenShift - addressed in versions 03.02.04.00, 03.04.01.00
xz-utils (Debian package) - update to 5.4.1-1
xz - update to 5.4.1-150600.3.3.1
liblzma5-64bit - update to 5.4.1-150600.3.3.1
xz-devel-64bit - update to 5.4.1-150600.3.3.1
liblzma5-64bit-debuginfo - update to 5.4.1-150600.3.3.1
xz-lang - update to 5.4.1-150600.3.3.1
liblzma5 - update to 5.4.1-150600.3.3.1
liblzma5-debuginfo - update to 5.4.1-150600.3.3.1
xz-debuginfo - update to 5.4.1-150600.3.3.1
xz-debugsource - update to 5.4.1-150600.3.3.1
xz-devel - update to 5.4.1-150600.3.3.1
xz-static-devel - update to 5.4.1-150600.3.3.1
liblzma5-32bit-debuginfo - update to 5.4.1-150600.3.3.1
liblzma5-32bit - update to 5.4.1-150600.3.3.1
xz-devel-32bit - update to 5.4.1-150600.3.3.1
xz - update to 5.4.7-2
xz-static - update to 5.4.7-2
xz-lzma-compat - update to 5.4.7-2
xz-libs - update to 5.4.7-2
xz-devel - update to 5.4.7-2
xz-help - update to 5.4.7-5
xz - update to 5.4.7-5
xz-debuginfo - update to 5.4.7-5
xz-debugsource - update to 5.4.7-5
xz-devel - update to 5.4.7-5
xz-libs - update to 5.4.7-5
xz-lzma-compat - update to 5.4.7-5
xz-utils (Ubuntu package) - addressed in versions 5.6.1+really5.4.5-1ubuntu0.2, 5.6.2-2ubuntu0.2
xz (Red Hat package) - update to 5.6.2-4.el10_0
app-arch/xz-utils - update to 5.6.4-r1
xz - addressed in versions 5.8.1-1.fc40, 5.8.1-1.fc41, 5.8.1-1.fc41.1, 5.8.1-1.fc42, 5.8.1-1.1.fc40

External References

Related Security Bulletins