Memory leak in xz - CVE-2025-58058

 

Memory leak in xz - CVE-2025-58058

Published: August 29, 2025


Vulnerability identifier: #VU114558
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-58058
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a DoS attack.

The vulnerability exists due memory leak when decoding corrupted LZMA archives. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

xz
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Fedora
HPC Module
Basesystem Module
openSUSE Leap
IBM Observability with Instana
Guardium Data Security Center (GDSC)
Maximo Application Suite - IoT Component
checkpointctl
apptainer
podman-tui
alloy-debuginfo
alloy
prometheus-podman-exporter
warewulf4-man
warewulf4-reference-doc
warewulf4-overlay-rke2
warewulf4-dracut
warewulf4-overlay-slurm
warewulf4
warewulf4-overlay
gdu
gitleaks
forgejo

How to mitigate CVE-2025-58058

Install updates from vendor's website.

xz - update to 0.5.14
IBM Observability with Instana - update to 1.0.309
Guardium Data Security Center (GDSC) - update to 3.8.5
Maximo Application Suite - IoT Component - addressed in versions 8.7.29, 8.8.26, 9.0.15, 9.1.6
checkpointctl - addressed in versions 1.4.0-1.el9, 1.4.0-1.fc41, 1.4.0-1.fc42, 1.4.0-1.fc43, 1.4.0-2.el9, 1.4.0-2.fc41, 1.4.0-2.fc42, 1.4.0-2.fc43, 1.4.0-3.el9, 1.4.0-3.fc41, 1.4.0-3.fc42, 1.4.0-3.fc43
apptainer - addressed in versions 1.4.3-1.el8, 1.4.3-1.el9, 1.4.3-1.el10_0, 1.4.3-1.el10_1, 1.4.3-1.el10_2, 1.4.3-1.fc41, 1.4.3-1.fc42, 1.4.3-2.fc43
podman-tui - addressed in versions 1.8.0-1.el10_2, 1.8.0-1.fc41, 1.8.0-1.fc42, 1.8.0-1.fc43, 1.8.0-2.el9
alloy-debuginfo - update to 1.11.3-150700.15.9.1
alloy - update to 1.11.3-150700.15.9.1
prometheus-podman-exporter - addressed in versions 1.18.1-1.el9, 1.18.1-1.el10_2, 1.18.1-1.fc41, 1.18.1-1.fc42, 1.18.1-1.fc43
warewulf4-man - update to 4.6.4-150500.6.37.1
warewulf4-reference-doc - update to 4.6.4-150500.6.37.1
warewulf4-overlay-rke2 - update to 4.6.4-150500.6.37.1
warewulf4-dracut - update to 4.6.4-150500.6.37.1
warewulf4-overlay-slurm - update to 4.6.4-150500.6.37.1
warewulf4 - update to 4.6.4-150500.6.37.1
warewulf4-overlay - update to 4.6.4-150500.6.37.1
gdu - update to 5.31.0-1.fc44
gitleaks - addressed in versions 8.28.0-1.fc41, 8.28.0-1.fc42, 8.28.0-1.fc43
forgejo - addressed in versions 12.0.3-1.el10_2, 12.0.3-1.fc42

External References

Related Security Bulletins