ALSA-2025:7524

Source
https://errata.almalinux.org/10/ALSA-2025-7524.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2025:7524.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALSA-2025:7524
Related
Published
2025-05-13T00:00:00Z
Modified
2025-05-29T10:02:23Z
Summary
Important: xz security update
Details

XZ Utils is an integrated collection of user-space file compression utilities based on the Lempel-Ziv-Markov chain algorithm (LZMA), which performs lossless data compression. The algorithm provides a high compression ratio while keeping the decompression time short.

Security Fix(es):

  • xz: XZ has a heap-use-after-free bug in threaded .xz decoder (CVE-2025-31115)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:10 / xz

Package

Name
xz
Purl
pkg:rpm/almalinux/xz

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:5.6.2-4.el10_0

AlmaLinux:10 / xz-devel

Package

Name
xz-devel
Purl
pkg:rpm/almalinux/xz-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:5.6.2-4.el10_0

AlmaLinux:10 / xz-libs

Package

Name
xz-libs
Purl
pkg:rpm/almalinux/xz-libs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:5.6.2-4.el10_0

AlmaLinux:10 / xz-lzma-compat

Package

Name
xz-lzma-compat
Purl
pkg:rpm/almalinux/xz-lzma-compat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:5.6.2-4.el10_0