XZ has a heap-use-after-free bug in threaded .xz decoder.
(CVE-2025-31115)
- https://bugs.mageia.org/show_bug.cgi?id=34164
- https://www.openwall.com/lists/oss-security/2025/04/03/1
- https://www.cve.org/CVERecord?id=CVE-2025-31115
- 9/core/xz-5.4.3-1.1.mga9
Get the latest Linux and open source security news straight to your inbox.