Opened 3 weeks ago

Closed 2 weeks ago

#6016 closed enhancement (fixed)

xz-5.8.4

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: normal Milestone: 13.2
Component: Book Version: git
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (3)

comment:1 by Joe Locash, 3 weeks ago

This contains a security fix: ​https://tukaani.org/xz/invalid-write-after-reinit.html

GHSA-5qpq-xqfv-j9pg: Invalid write if a decoder is reinitialized after allocation failure

2026-09-09

In XZ Utils 5.8.3 and older, an invalid memory write can occur in decoders that are initialized using the following functions:

  • lzma_alone_decoder (decodes .lzma files)
  • lzma_lzip_decoder (decodes .lz files)
  • lzma_auto_decoder (when decoding .lzma or .lz files)
  • lzma_microlzma_decoder (decodes MicroLZMA format)

Required steps:

  1. A lzma_stream is initialized using one of the above functions.
  2. A file is decoded at least partially.
  3. The same lzma_stream is reinitialized using the same function.
  4. Another file is decoded but memory allocation fails with LZMA_MEM_ERROR. (LZMA_MEMLIMIT_ERROR doesn’t cause this.)
  5. The same lzma_stream is reinitialized again using the same function.
  6. A file is decoded. It must specify the same dictionary size as the file in step 2.

Decoders for the .xz format and raw streams aren’t affected.

The issue has been fixed in XZ Utils 5.8.4 and in the Git repository branch v5.8. The fix is also in the Git repository branches v5.6, v5.4, and v5.2, but no new releases will be made from these old branches.

The bug was reported and discovered by Cantina using their AppSec agent, Apex.

comment:2 by Bruce Dubbs, 2 weeks ago

Owner: changed from lfs-book to SecurityAdvisory

Updated at commit 9a4ceea7b. Leaving open for advisories.

comment:3 by Bruce Dubbs, 2 weeks ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.1-024 has been issued.

Note: See TracTickets for help on using tickets.