| Message ID | 20260913171230.3920551-31-adolf.belka@ipfire.org |
|---|---|
| State | New |
| Headers |
Return-Path: <development+bounces-2628-patchwork=ipfire.org@lists.ipfire.org> Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hjZcH1R3cz3xTV for <patchwork@web04.haj.ipfire.org>; Sun, 13 Sep 2026 17:13:19 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hjZcG6NyCz6kq for <patchwork@ipfire.org>; Sun, 13 Sep 2026 17:13:18 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hjZbl754jz37g2 for <patchwork@ipfire.org>; Sun, 13 Sep 2026 17:12:51 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hjZbh0y6dz37Jf for <development@lists.ipfire.org>; Sun, 13 Sep 2026 17:12:48 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4hjZbd0vSZz8Zx; Sun, 13 Sep 2026 17:12:45 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1789319565; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=xZFPoLH4EYGllr8MB1eYJ1HXaV/6ugD7fSDjt2BqLJU=; b=8jjWfLb3TyCUor+5Am4WXb/GoQFADZnq4/O1Wd3fpC0pDuFYeakvaphAiV91Yea+IkLzCd dwBvERFQZ1CwAaDg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1789319565; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=xZFPoLH4EYGllr8MB1eYJ1HXaV/6ugD7fSDjt2BqLJU=; b=jy48WCKOWgE8vZDHd30daoBzGpPmapRb7ByvOYGhz2tshnE+iBtGKMW7LaIi4U+4WlFagC kqOIk4JsvGFUFgozzn3HYzcuwfXGIvK9ckMtaCukbe2LaWgxNGlg07c9pqBijRCRJONNCO o2R/6Eql04LpF+Hd1WbPLDrB6oZXmD9ao3B2XHc/x4JfqOLJH7uhq+bPVclCED7yAdz4Bl Eb8CCMqJJD+eFA7AU0cVto0b3tC+ze19oNba5sSlr9r78PMRa+iPo6z9JYfiVyiKVYjgwQ PD8YMmMIWnmyQ2fsevEhpXSu5eIlckFcu6i3HTB5hCyZGr0kNFZyBpVb7suIjw== From: Adolf Belka <adolf.belka@ipfire.org> To: development@lists.ipfire.org Cc: Adolf Belka <adolf.belka@ipfire.org> Subject: [PATCH] xz: Update to version 5.8.4 Date: Sun, 13 Sep 2026 19:12:30 +0200 Message-ID: <20260913171230.3920551-31-adolf.belka@ipfire.org> In-Reply-To: <20260913171230.3920551-1-adolf.belka@ipfire.org> References: <20260913171230.3920551-1-adolf.belka@ipfire.org> Precedence: list List-Id: <development.lists.ipfire.org> List-Subscribe: <https://lists.ipfire.org/>, <mailto:development+subscribe@lists.ipfire.org?subject=subscribe> List-Unsubscribe: <https://lists.ipfire.org/>, <mailto:development+unsubscribe@lists.ipfire.org?subject=unsubscribe> List-Post: <mailto:development@lists.ipfire.org> List-Help: <mailto:development+help@lists.ipfire.org?subject=help> Sender: <development@lists.ipfire.org> Mail-Followup-To: <development@lists.ipfire.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit |
| Series |
xz: Update to version 5.8.4
|
|
Commit Message
Adolf Belka
13 Sep 2026, 5:12 p.m. UTC
- Update from version 5.8.3 to 5.8.4
- Update of rootfile
- 1 GHSA security fix
- Changelog
5.8.4
IMPORTANT: This includes a fix for a security issue that affects all
XZ Utils versions since 5.0.0. This and a few other fixes have also
been committed to the old stable branches (v5.2, v5.4, and v5.6) in
the xz Git repository. Those fixes are marked below. No new 5.2.x,
5.4.x, or 5.6.x releases will be made.
* liblzma:
- lzma_alone_decoder(), lzma_lzip_decoder(),
lzma_auto_decoder(), and lzma_microlzma_decoder(): Fix an
invalid memory access after memory allocation has failed and
the application reinitializes the existing decoder to decode
a different file. This bug could at least result in a crash.
This is tracked as GHSA-5qpq-xqfv-j9pg. CVE number is pending.
(Also in v5.2, v5.4, and v5.6.)
- lzma_stream_buffer_decode(): Fix wrong error code and,
in debug builds, assertion failure. LZMA_BUF_ERROR could
be returned with truncated inputs while LZMA_DATA_ERROR
is the correct one in this function.
(Also in v5.2, v5.4, and v5.6.)
- Fix a performance issue in the typical use case of
lzma_index_cat(). Internally liblzma calls it from
lzma_file_info_decoder(), so that was affected too. The
problem occurred if the input .xz file was created by
concatenating a large number of .xz files. A crafted file
could make "xz --list" very slow or effectively hang.
Normal decompression doesn't use these functions and
thus wasn't affected.
(Also in v5.2, v5.4, and v5.6.)
- Fix a theoretical integer overflow in lzma_index_cat().
(Also in v5.2, v5.4, and v5.6.)
- Fix bogus memory usage report in lzma_index_decoder() when
the .xz Index is obviously invalid. A huge bogus value could
cause an integer overflow in lzma_file_info_decoder()'s
memory usage reporting due to a missing overflow check,
making lzma_memused() report an incorrect tiny value. This
bug didn't affect the memory usage limiter in these two
decoders; only the reporting via lzma_memused() was affected.
(Also in v5.2, v5.4, and v5.6.)
- Fix a too low memory usage report in lzma_index_decoder()
if lzma_memused() is called after a part of the Index has
already been decoded. The typical use case is to call
lzma_memused() immediately after LZMA_MEMLIMIT_ERROR,
which did work correctly.
- Fix copying of check type in lzma_index_dup(). Calling
lzma_index_checks() on the duplicated lzma_index returned
return garbage a result. lzma_index_dup() is rarely used;
liblzma doesn't use it internally and xz itself doesn't use
it either.
(Also in v5.2, v5.4, and v5.6.)
- lzma_file_info_decoder() and lzma_index_decoder(): Reject
an obviously-invalid Number of Records field earlier.
(Partially also in v5.2, v5.4, and v5.6.)
- Fix a missing synchronization in the threaded .xz decoder. It
could make lzma_get_progress() return incorrect progress info.
(Also in v5.4 and v5.6.)
- Detect certain kinds of corrupt inputs slightly earlier in
the LZMA2 decoder.
- ARM64 and LoongArch: Don't use aligned reads on unaligned
buffers. This makes the code work on strict-align processors
and fixes a sanitizer error in other cases. (Since 5.7.1alpha)
* xz:
- Fix a use-after-free when showing an error message if --files
or --files0 was specified in the environment variables XZ_OPT
or XZ_DEFAULTS.
(Also in v5.2, v5.4, and v5.6.)
- Fix a use-after-free bug when --verbose is used and
standard error isn't a terminal. (Since 5.7.1alpha)
- Make it an error if the totals in "xz --list" exceed the range
of 64-bit integers.
(Also in v5.2, v5.4, and v5.6.)
* xz and xzdec on Linux:
- Add support for Landlock ABI version 9.
- Use fallback macros for Landlock ABI version 2, 3, and 5
(but not 4) if <linux/landlock.h> is older than ABI version 5.
This makes the binary slightly more protected if it is run on
a kernel that supports newer ABIs than <linux/landlock.h>.
* Scripts:
- xzgrep: Fix handling of the ' char at the end of a command
line option. For example, the following tricked xzgrep to
run "id": xzgrep "-e'" "-e;id;'" somefile
(Also in v5.2, v5.4, and v5.6.)
- xzdiff: Use the C locale (LC_ALL=C) with "sed" and "expr"
to ensure safe behavior with invalid multibyte sequences.
An equivalent improvement was made in xzgrep in 5.2.6
(2022-08-12), but it was forgotten from xzdiff.
(Also in v5.2, v5.4, and v5.6.)
* Tests:
- Improve a few tests and fuzz targets.
- Add new test files:
* bad-0-index-1.xz (32 bytes)
* bad-1-index-huge-uncomp.xz (72 bytes)
* Man pages:
- Improve the rendering with OpenBSD's mandoc(1).
- Reduce indentation of the tables to avoid overlong lines
in translated versions of the xz man page.
* Translations:
- In translated man pages, workaround an issue with non-ASCII
characters in tables.
- Fix syntax errors in a few man page translations.
- Update Arabic and German man page translations.
- Update Brazilian Portuguese, Croatian, Dutch, German, Italian,
Korean, Polish, Portuguese, Romanian, and Ukrainian message
translations.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/xz | 2 +-
lfs/xz | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/config/rootfiles/common/xz b/config/rootfiles/common/xz index 5debdf404..d7af0fa4d 100644 --- a/config/rootfiles/common/xz +++ b/config/rootfiles/common/xz @@ -41,7 +41,7 @@ usr/bin/xzmore #usr/lib/liblzma.la #usr/lib/liblzma.so usr/lib/liblzma.so.5 -usr/lib/liblzma.so.5.8.3 +usr/lib/liblzma.so.5.8.4 #usr/lib/pkgconfig/liblzma.pc #usr/share/doc/xz #usr/share/doc/xz/AUTHORS diff --git a/lfs/xz b/lfs/xz index a8de6c5d7..b0c90d790 100644 --- a/lfs/xz +++ b/lfs/xz @@ -24,7 +24,7 @@ include Config -VER = 5.8.3 +VER = 5.8.4 THISAPP = xz-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -45,7 +45,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 36d6ae3ce1ee70f1d18d10107f7d6b4dfb43c34e11d8ec4504feeaa50b43cfa8d80de2b8ac2a1b66478723a83b4ebacf4179b69fb4d746f08b120b2e804fc2ce +$(DL_FILE)_BLAKE2 = 917cd5c0b8bf296d15b6d868a6be3910f73e06f96eb2e17a2064902c3635268a4b0aca9f8c617a402cffc10e06e4e12d998bacf8db81f084cf62e46f3485fb51 install : $(TARGET)