PatchSiren

tukaani-project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW tukaani-project CVE published 2026-04-02

CVE-2026-34743

The CVE record describes a buffer overflow vulnerability in XZ Utils. If lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3. Affected product deployments should be identified, and owner [truncated]