XZ Utils 5.8.1 update addresses vulnerability

The release of XZ Utils 5.8.1 has been published, which includes the liblzma library and utilities for working with compressed data in the "xz" format. XZ Utils 5.8.1 is the first significant release after the incident involving the discovery of a backdoor facilitating access through sshd. Last week, a tag 5.8.0 was created in Git, but the release was not officially announced due to performance and compatibility issues with older versions of GNU make that were identified after the tag was published.

The XZ Utils 5.8.1 update addresses a vulnerability (CVE-2025-31115) that causes a crash when attempting to unpack specially crafted archives. The vulnerability is due to accessing a previously freed memory area (use after free). An attacker can achieve the writing of their value to an address calculated as "null pointer + offset." The issue is considered an accidental error, as the change that caused it was made in the code long before developer Jia Tan joined the project, whose activities led to the introduction of the backdoor.

The issue manifests starting with the release of XZ Utils 5.3.3alpha when decoding in multithreaded mode (single-threaded decoders are not affected). In addition to the standard utilities from the xz package, the vulnerability also appears in third-party programs using the lzma_stream_decoder_mt function from the liblzma library. The vulnerability has been fixed in the release of XZ Utils 5.8.1, and it has also been backported to stable branches 5.4 and 5.6. You can track the appearance of updates in distributions on the following pages: Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch, FreeBSD. As a workaround for protection, you can disable multithreaded file decoding by using the options "--decompress --threads=1" when starting xz or by using the xzdec utility.

Key functional changes in the XZ Utils 5.8 branch include:

  • In the LZMA/LZMA2 decoder, the ability to use SSE2 instructions instead of the memcpy() function on 32- and 64-bit x86 systems has been added. This change allows for a reduction in decoding time of up to 5% when built with Glibc and up to 15% when built with musl while unpacking files with very high compression levels.
  • In liblzma, the encoding speed has been increased on 64-bit PowerPC and RISC-V systems.
  • A low-level API for BCJ filters (Branch/Call/Jump) has been added in lzma/bcj.h for RISC-V, ARM64, and x86 systems.
  • The code for computing CLMUL CRC for x86, x86-64, and E2K systems has been rewritten.
  • On platforms with LoongArch processors, instructions are utilized to accelerate the calculation of CRC32 checksums.
  • In the 'xz' utility, the fsync() function is called to flush file caches for the resulting file before removing the original file. The ‘—no-sync’ option has been implemented to disable synchronization before deletion.
  • In the xz, xzdec, and lzmainfo utilities, non-printable characters are replaced with a question mark when outputting information to the screen.
  • In xz and xzdec on the Linux platform, support for versions 5 and 6 of the Landlock mechanism has been implemented to isolate processes.
  • A script for license checking build-aux/license-check.sh has been added.
  • The scripts lzcmp, lzdiff, lzless, lzmore, lzgrep, lzegrep, and lzfgrep, which were implemented as extensions to the xz utility, have been deprecated.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster