ELA-1844-1 xz-utils security update

multiple vulnerabilities

2026-10-09
Packagexz-utils
Version5.2.2-1.2+deb9u2 (stretch), 5.2.4-1+deb10u2 (buster)
Related CVEs CVE-2026-34743


Two issues were discovered in xz-utils, an XZ-format compression library and utilities, which may lead to memory corruption in specific situations.

The second issue has no CVE assigned and is currently referenced as GHSA-5qpq-xqfv-j9pg.



For Debian 10 buster, these problems have been fixed in version 5.2.4-1+deb10u2.

For Debian 9 stretch, these problems have been fixed in version 5.2.2-1.2+deb9u2.

We recommend that you upgrade your xz-utils packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.