Opened 3 weeks ago
Closed 2 weeks ago
#6016 closed enhancement (fixed)
xz-5.8.4
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | normal | Milestone: | 13.2 |
| Component: | Book | Version: | git |
| Severity: | normal | Keywords: | |
| Cc: |
Description
New point version.
Change History (3)
comment:1 by , 3 weeks ago
comment:2 by , 2 weeks ago
| Owner: | changed from to |
|---|
Updated at commit 9a4ceea7b. Leaving open for advisories.
comment:3 by , 2 weeks ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.1-024 has been issued.
Note:
See TracTickets
for help on using tickets.

This contains a security fix: https://tukaani.org/xz/invalid-write-after-reinit.html
GHSA-5qpq-xqfv-j9pg: Invalid write if a decoder is reinitialized after allocation failure
2026-09-09
In XZ Utils 5.8.3 and older, an invalid memory write can occur in decoders that are initialized using the following functions:
Required steps:
Decoders for the .xz format and raw streams aren’t affected.
The issue has been fixed in XZ Utils 5.8.4 and in the Git repository branch v5.8. The fix is also in the Git repository branches v5.6, v5.4, and v5.2, but no new releases will be made from these old branches.
The bug was reported and discovered by Cantina using their AppSec agent, Apex.