Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
xz 5.8.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4871b31998 2025-05-10 01:38:46.492145+00:00 -------------------------------------------------------------------------------- Name : xz Product : Fedora 40 Version : 5.8.1 Release : 2.fc40 URL : https://tukaani.org/xz/ Summary : LZMA compression utilities Description : XZ Utils are an attempt to make LZMA compression easy to use on free (as in freedom) operating systems. This is achieved by providing tools and libraries which are similar to use than the equivalents of the most popular existing compression algorithms. LZMA is a general purpose compression algorithm designed by Igor Pavlov as part of 7-Zip. It provides high compression ratio while keeping the decompression speed fast. -------------------------------------------------------------------------------- Update Information: xz 5.8.1 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 24 2025 Adam Williamson - 1:5.8.1-2 - Rebuild without changes to fix gating problem * Thu Apr 3 2025 Richard W.M. Jones - 1:5.8.1-1 - New upstream version 5.8.1 - Fixes CVE-2025-31115 heap-use-after-free bug in threaded .xz decoder * Wed Mar 26 2025 Jakub Martisko - 1:5.8.0-1 - New upstream version 5.8.0 Resolves: rhbz#2341818 * Sun Jan 19 2025 Fedora Release Engineering - 1:5.6.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Fri Oct 11 2024 Richard W.M. Jones - 1:5.6.3-2 - perl-Compress-Raw-Lzma dep has been removed, rebuild https://src.fedoraproject.org/rpms/perl-Compress-Raw-Lzma/pull-request/3 * Wed Oct 2 2024 Richard W.M. Jones - 1:5.6.3-1 - New upstream version 5.6.3 (RHBZ#2316069) * Thu Aug 8 2024 Lukáš Zaoral - 1:5.6.2-3 - fix licenses and finish SPDX license conversion * Sat Jul 20 2024 Fedora Release Engineering - 1:5.6.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Thu Jun20 2024 Richard W.M. Jones - 1:5.6.2-1 - New upstream version 5.6.2 (RHBZ#2283854) - Remove "Jia Tan" pubkey, replace with Lasse Collin's. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2357251 - CVE-2025-31115 xz: XZ has a heap-use-after-free bug in threaded .xz decoder [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2357251 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4871b31998' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . The xz 5.8.1 update on Fedora 40 addresses a critical heap-use-after-free vulnerability found in the secure compression tool.. Fedora xz update, compression utilities, Fedora security, LZMA compression. . Severity: Critical. LinuxSecurity.com Team
New upstream version 5.8.1 (with a rebuild to try and fix a gating problem). New upstream version 5.8.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7f00e5e744 2025-04-26 01:55:23.747817+00:00 -------------------------------------------------------------------------------- Name : xz Product : Fedora 42 Version : 5.8.1 Release : 2.fc42 URL : https://tukaani.org/xz/ Summary : LZMA compression utilities Description : XZ Utils are an attempt to make LZMA compression easy to use on free (as in freedom) operating systems. This is achieved by providing tools and libraries which are similar to use than the equivalents of the most popular existing compression algorithms. LZMA is a general purpose compression algorithm designed by Igor Pavlov as part of 7-Zip. It provides high compression ratio while keeping the decompression speed fast. -------------------------------------------------------------------------------- Update Information: New upstream version 5.8.1 (with a rebuild to try and fix a gating problem). New upstream version 5.8.1 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 24 2025 Adam Williamson - 1:5.8.1-2 - Empty rebuild to try and fix gating issue * Thu Apr 3 2025 Richard W.M. Jones - 1:5.8.1-1 - New upstream version 5.8.1 - Fixes CVE-2025-31115 heap-use-after-free bug in threaded .xz decoder * Wed Mar 26 2025 Jakub Martisko - 1:5.8.0-1 - New upstream version 5.8.0 Resolves: rhbz#2341818 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7f00e5e744' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
5.0.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f050ec7d1b 2025-04-11 18:19:12.061671+00:00 -------------------------------------------------------------------------------- Name : upx Product : Fedora 42 Version : 5.0.0 Release : 1.fc42 URL : https://github.com/upx/upx Summary : Ultimate Packer for eXecutables Description : UPX is a free, portable, extendable, high-performance executable packer for several different executable formats. It achieves an excellent compression ratio and offers very fast decompression. Your executables suffer no memory overhead or other drawbacks. -------------------------------------------------------------------------------- Update Information: 5.0.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 20 2025 Gwyn Ciesla - 5.0.0-1 - 5.0.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2355649 - CVE-2025-2849 upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2355649 [ 2 ] Bug #2355650 - CVE-2025-2849 upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2355650 [ 3 ] Bug #2355651 - CVE-2025-2849 upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2355651 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f050ec7d1b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project canbe found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Andres Freund discovered that the upstream source tarballs for xz-utils, the XZ-format compression utilities, are compromised and inject malicious code, at build time, into the resulting liblzma5 library. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5649-1
It was discovered that zstd, a compression utility, was vulnerable to a race condition: it temporarily exposed, during a very short timeframe, a world-readable version of its input even if the original file had restrictive permissions. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2573-1
It was discovered that zstd, a compression utility, temporarily exposed a world-readable version of its input even if the original file had restrictive permissions. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4850-1
LHa has a buffer overflow in its compression utility with unspecified impact.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202007-42 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: LHa: Buffer overflow Date: July 27, 2020 Bugs: #572418 ID: 202007-42 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= LHa has a buffer overflow in its compression utility with unspecified impact. Background ========= LHa is a console-based program for packing and unpacking LHarc archives. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-arch/lha < 114i_p20201004 > = 114i_p20201004 Description ========== A buffer overflow in LHa's compression code was discovered which can be triggered by a crafted input file. Impact ===== A remote attacker could send a specially crafted file possibly resulting in a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All LHa users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/lha-114i_p20201004" References ========= [ 1 ] CVE-2016-1925 https://nvd.nist.gov/vuln/detail/CVE-2016-1925 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202007-42 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Anysecurity concerns should be addressed to
- Update to GIT 20200421 - Added patch against race condition in setting permissions on output file (#1182024) - Added patch to revert environment redirect allowing `export XZ_OPT="-9"` or similar. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-8b89d5b9eb 2020-05-01 04:04:10.484407 --------------------------------------------------------------------------------Name : pxz Product : Fedora 32 Version : 4.999.9 Release : 19.beta.20200421git.fc32 URL : https://jnovy.fedorapeople.org/pxz/ Summary : Parallel LZMA compressor using XZ Description : Parallel XZ is a compression utility that takes advantage of running XZ compression simultaneously on different parts of an input file on multiple cores and processors. This significantly speeds up compression time. --------------------------------------------------------------------------------Update Information: - Update to GIT 20200421 - Added patch against race condition in setting permissions on output file (#1182024) - Added patch to revert environment redirect allowing `export XZ_OPT="-9"` or similar --------------------------------------------------------------------------------ChangeLog: * Tue Apr 21 2020 Robert Scheck 4.999.9-19.beta.20200421git - Update to GIT 20200421 - Added patch against race condition in setting permissions on output file (#1182024) - Added patch to revert environment redirect allowing 'export XZ_OPT="-9"' or similar --------------------------------------------------------------------------------References: [ 1 ] Bug #1182024 - CVE-2015-1200 pxz: race condition in setting permissions on output file https://bugzilla.redhat.com/show_bug.cgi?id=1182024 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-8b89d5b9eb' at the command line. For more information, refer tothe dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.