| Package | xz-utils |
|---|---|
| Version | 5.2.5-2.1~deb11u3 (bullseye) |
An invalid write was discovered in xz-utils, an XZ-format compression library and utilities, which may lead to memory corruption in specific situations.
This issue has no CVE assigned and is currently referenced as GHSA-5qpq-xqfv-j9pg.
For Debian 11 bullseye, these problems have been fixed in version 5.2.5-2.1~deb11u3.
We recommend that you upgrade your xz-utils packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.