Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34743

25
FAUCET Score

CVE-2026-34743 is a buffer overflow vulnerability affecting XZ Utils versions prior to 5.8.3. It occurs when the lzma_index_decoder() function processes an empty index, causing subsequent operations to allocate insufficient memory. Rated with a CVSSv4 score of 1.7 (LOW), this vulnerability has a network attack vector and low attack complexity, with its primary impact being limited system availability. There is no evidence of active exploitation, nor is public exploit code available in common databases like Metasploit or ExploitDB, and community discussion remains minimal.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.8.3CPE matchmatch criteria
cpe:2.3:a:tukaani:xz:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

1.7LOW

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.45%
Probability of exploitation in next 30 days
EPSS Percentile
36.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0045 is in the 23rd percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (20)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 xz 5.4.4-3 on Azure Linux 3.0Fixed in: 5.4.4-3
microsoftpatch availablevia msrc
Product: cbl2 xz 5.2.5-1 on CBL Mariner 2.0Fixed in: 5.2.5-2
microsoftpatch availablevia msrc
Product: azl3 rust 1.75.0-27 on Azure Linux 3.0Fixed in: 1.75.0-28
microsoftpatch availablevia msrc
Product: cbl2 rust 1.72.0-15 on CBL Mariner 2.0Fixed in: 1.72.0-16
microsoftpatch availablevia msrc
Product: azl3 rust 1.90.0-6 on Azure Linux 3.0Fixed in: 1.90.0-7
microsoftpatch availablevia msrc
Product: 21110-17084Fixed in: 1.75.0-28
microsoftpatch availablevia msrc
Product: 21108-17086Fixed in: 1.72.0-16
microsoftpatch availablevia msrc
Product: 21123-17084Fixed in: 1.90.0-7
microsoftpatch availablevia msrc
Product: azl3 xz 5.4.4-2 on Azure Linux 3.0Fixed in: 5.4.4-3
microsoftpatch availablevia msrc
Product: 19442-17084Fixed in: 5.4.4-3
microsoftpatch availablevia msrc
Product: 21212-17084Fixed in: 5.4.4-3
microsoftpatch availablevia msrc
Product: 21167-17086Fixed in: 5.2.5-2
ubuntupatch availablevia ubuntu_usn
Product: xz-utils (questing)Fixed in: 5.8.1-1ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: xz-utils (trusty)Fixed in: 5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2
ubuntupatch availablevia ubuntu_usn
Product: xz-utils (xenial)Fixed in: 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
ubuntupatch availablevia ubuntu_usn
Product: xz-utils (bionic)Fixed in: 5.2.2-1.3ubuntu0.1+esm1
ubuntupatch availablevia ubuntu_usn
Product: xz-utils (focal)Fixed in: 5.2.4-1ubuntu1.1+esm1
ubuntupatch availablevia ubuntu_usn
Product: xz-utils (jammy)Fixed in: 5.2.5-2ubuntu1.1
ubuntupatch availablevia ubuntu_usn
Product: xz-utils (noble)Fixed in: 5.6.1+really5.4.5-1ubuntu0.3

Vendor Advisories (2)

ubuntuUSN-8362-1

XZ Utils vulnerability

Jun 2, 2026
microsoft2026-Apr/CVE-2026-34743Low

XZ Utils: Buffer overflow in lzma_index_append()

Apr 2, 2026

References

lists.debian.org / debian-lts-announce/2026/07/msg00034.html
openwall.com / lists/oss-security/2026/03/31/13
Mailing ListPatchThird Party Advisory
github.com / tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87
Patch
github.com / tukaani-project/xz/releases/tag/v5.8.3
ProductRelease Notes
github.com / tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv
Vendor Advisory