Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 15 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tukaani
Tukaani xz |
|
| CPEs | cpe:2.3:a:tukaani:xz:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tukaani
Tukaani xz |
Sat, 04 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-131 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 03 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tukaani-project
Tukaani-project xz |
|
| Vendors & Products |
Tukaani-project
Tukaani-project xz |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3. | |
| Title | XZ Utils: Buffer overflow in lzma_index_append() | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-03T12:59:06.096Z
Reserved: 2026-03-30T19:17:10.224Z
Link: CVE-2026-34743
Updated: 2026-04-02T19:24:10.537Z
Status : Analyzed
Published: 2026-04-02T19:21:33.187
Modified: 2026-04-15T17:33:17.680
Link: CVE-2026-34743
OpenCVE Enrichment
Updated: 2026-04-07T07:55:30Z