Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-462

JLSEC-2026-462

JLSEC Published
Modified
Affected Packages
XZ_jll < 5.8.3+0
Aliases / Upstream
CVE-2026-34743

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzmaindexdecoder() was used to decode an Index that contained no Records, the resulting lzmaindex was left in a state where where a subsequent lzmaindex_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.

References