CVE-2021-29482

unknown
Published 2021-05-25 · Modified 2024-05-20
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk

Description

xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. The problem has been fixed in release v0.5.8. As a workaround users can limit the size of the compressed file input to a reasonable size for their use case. The standard library had recently the same issue and got the CVE-2020-16845 allocated.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-29482

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.5.6-2
debian debianbullseyefixed0.5.6-2
debian debianforkyfixed0.5.6-2
debian debiansidfixed0.5.6-2
debian debiantrixiefixed0.5.6-2

Package impact

EcosystemPackageVulnerableFixed
golang Gogithub.com/ulikunitz/xz<0.5.80.5.8

References

Verify integrity in audit chain (admin only). AS-IS.