CVE-2025-31115 is a critical vulnerability in XZ Utils versions 5.3.3alpha to 5.8.0, specifically impacting the multithreaded .xz decoder in liblzma. Invalid input can lead to crashes, heap use-after-free, and writes to arbitrary memory locations, affecting applications and libraries utilizing the lzma_stream_decoder_mt function. With a CVSS score of 8.7 (HIGH), this vulnerability presents a significant risk due to its network-based attack vector and low attack complexity, potentially leading to high availability impact. While no active exploitation, public exploit code, or significant community discussion has been observed, a fix is available in XZ Utils 5.8.1 and as a standalone patch for affected versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Tukaani-Project | Xz | >= 5.3.3alpha, < 5.8.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.