CVE Feed

    Dashboard / CVE / CVE-2026-34743

    CVE-2026-34743

    XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

    Published:Apr 2, 2026
    Last Modified:Apr 15, 2026
    EPS:Apr 2, 2026
    EPSS Score:0.00056
    CVSS Score:5.3

    Affected Products

    Vendor
    Tukaani
    Product
    Xz
    Vendor
    Tukaani-project
    Product
    Xz

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High