CVE-2026-34743 | tukaani-project xz up to 5.8.2 Compression lzma_index_decoder heap-based overflow (GHSA-x872-m794-cxhv)
A vulnerability marked as critical has been reported in tukaani-project xz up to 5.8.2. This impacts the function lzma_index_decoder of the component Compression Handler. Performing a manipulation results in heap-based buffer overflow.
This vulnerability was named CVE-2026-34743. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.