Heap-based buffer overflow in XZ Utils - CVE-2025-31115
Published: April 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the lzma_stream_decoder_mt() function. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
FreeBSD
Basesystem Module
openSUSE Leap
Anolis OS
openEuler
Ubuntu
Fedora
IBM Observability with Instana
APEX Cloud Platform for Red Hat OpenShift
Storage Defender - Resiliency Service
APEX Cloud Platform for Microsoft Azure
SmartFabric Manager
perl-Compress-Raw-Lzma
xz-utils (Debian package)
xz
liblzma5-64bit
xz-devel-64bit
liblzma5-64bit-debuginfo
xz-lang
liblzma5
liblzma5-debuginfo
xz-debuginfo
xz-debugsource
xz-devel
xz-static-devel
liblzma5-32bit-debuginfo
liblzma5-32bit
xz-devel-32bit
xz-static
xz-lzma-compat
xz-libs
xz-help
xz-utils (Ubuntu package)
xz (Red Hat package)
app-arch/xz-utils
How to mitigate CVE-2025-31115
IBM Observability with Instana - update to 1.0.297
Storage Defender - Resiliency Service - update to 2.0.14
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
perl-Compress-Raw-Lzma - addressed in versions 2.209-9.fc40, 2.212-6.fc41
APEX Cloud Platform for Red Hat OpenShift - addressed in versions 03.02.04.00, 03.04.01.00
xz-utils (Debian package) - update to 5.4.1-1
xz - update to 5.4.1-150600.3.3.1
liblzma5-64bit - update to 5.4.1-150600.3.3.1
xz-devel-64bit - update to 5.4.1-150600.3.3.1
liblzma5-64bit-debuginfo - update to 5.4.1-150600.3.3.1
xz-lang - update to 5.4.1-150600.3.3.1
liblzma5 - update to 5.4.1-150600.3.3.1
liblzma5-debuginfo - update to 5.4.1-150600.3.3.1
xz-debuginfo - update to 5.4.1-150600.3.3.1
xz-debugsource - update to 5.4.1-150600.3.3.1
xz-devel - update to 5.4.1-150600.3.3.1
xz-static-devel - update to 5.4.1-150600.3.3.1
liblzma5-32bit-debuginfo - update to 5.4.1-150600.3.3.1
liblzma5-32bit - update to 5.4.1-150600.3.3.1
xz-devel-32bit - update to 5.4.1-150600.3.3.1
xz - update to 5.4.7-2
xz-static - update to 5.4.7-2
xz-lzma-compat - update to 5.4.7-2
xz-libs - update to 5.4.7-2
xz-devel - update to 5.4.7-2
xz-help - update to 5.4.7-5
xz - update to 5.4.7-5
xz-debuginfo - update to 5.4.7-5
xz-debugsource - update to 5.4.7-5
xz-devel - update to 5.4.7-5
xz-libs - update to 5.4.7-5
xz-lzma-compat - update to 5.4.7-5
xz-utils (Ubuntu package) - addressed in versions 5.6.1+really5.4.5-1ubuntu0.2, 5.6.2-2ubuntu0.2
xz (Red Hat package) - update to 5.6.2-4.el10_0
app-arch/xz-utils - update to 5.6.4-r1
xz - addressed in versions 5.8.1-1.fc40, 5.8.1-1.fc41, 5.8.1-1.fc41.1, 5.8.1-1.fc42, 5.8.1-1.1.fc40
External References
Related Security Bulletins
- Remote code execution in XZ Utils
- Ubuntu update for xz-utils
- Fedora 42 update for xz
- Fedora 41 update for xz
- Fedora 40 update for xz
- SUSE update for xz
- Fedora 40 update for perl-Compress-Raw-Lzma, xz
- Fedora 41 update for perl-Compress-Raw-Lzma, xz
- Gentoo update for XZ Utils
- Debian update for xz-utils
- Anolis OS update for xz
- openEuler 24.03 LTS SP1 update for xz
- openEuler 24.03 LTS update for xz
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Red Hat Enterprise Linux 10 update for xz
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Dell SmartFabric Manager update for third-party components
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- FreeBSD update for xz decoder