CVE-2026-34743 - Medium Severity Vulnerability
Vulnerable Library - xzv5.8.2
XZ Utils
Library home page: https://github.com/tukaani-project/xz.git
Found in base branch: stable/4.0
Vulnerable Source Files (1)
/liblzma/common/index.c
Vulnerability Details
XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.
Publish Date: 2026-04-02
URL: CVE-2026-34743
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-02
Fix Resolution: https://github.com/tukaani-project/xz.git - v5.8.3
Step up your Open Source Security Game with Mend here
CVE-2026-34743 - Medium Severity Vulnerability
XZ Utils
Library home page: https://github.com/tukaani-project/xz.git
Found in base branch: stable/4.0
XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.
Publish Date: 2026-04-02
URL: CVE-2026-34743
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-04-02
Fix Resolution: https://github.com/tukaani-project/xz.git - v5.8.3
Step up your Open Source Security Game with Mend here