XZ has a heap-use-after-free bug in threaded .xz decoder. (CVE-2025-31115) References: - https://bugs.mageia.org/show_bug.cgi?id=34164 . MGASA-2025-0131 - Updated xz packages fix security vulnerability Publication date: 10 Apr 2025 URL: https://advisories.mageia.org/MGASA-2025-0131.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-31115 XZ has a heap-use-after-free bug in threaded .xz decoder. (CVE-2025-31115) References: - https://bugs.mageia.org/show_bug.cgi?id=34164 - https://www.openwall.com/lists/oss-security/2025/04/03/1 - https://www.cve.org/CVERecord?id=CVE-2025-31115 SRPMS: - 9/core/xz-5.4.3-1.1.mga9 . Mageia 9 has released a notice concerning xz packages because of a heap-use-after-free vulnerability. Discover more about the resolution.. Mageia 9, xz security, heap use after free, software vulnerability. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.