XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The effects include heap use after free and writing to an address based on the null pointer plus an offset. Applications and libraries that use the lzma_stream_decoder_mt function are affected. The bug has been fixed in XZ Utils 5.8.1, and the fix has been committed to the v5.4, v5.6, v5.8, and master branches in the xz Git repository. No new release packages will be made from the old stable branches, but a standalone patch is available that applies to all affected releases.
Conclusion & alert: CVE-2025-31115 is rated Moderate Risk (50.5/100): CVSS High severity, with low exploitation likelihood (EPSS 0.59%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.04% | 0.59% | +0.55% |
| 2 | 2026-05-12 | 0.31% | 0.04% | -0.27% |
| 3 | 2026-01-28 | — | 0.31% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 4.0 | HIGH |
|
— | — | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2025-31115: 1 source package rows (xz); 20 state rows across 7 repos (3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, 3.23-main, edge-main); fixed 13, open 7. | https://security.alpinelinux.org/vuln/CVE-2025-31115 |
debian
|
unimportant | CVE-2025-31115 unimportant priority: Debian including 1 source packages (xz-utils), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2025-31115 |
gentoo
|
normal | CVE-2025-31115: 1 GLSA(s) (202504-01), 1 atom(s) (app-arch/xz-utils); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2025-31115 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-31115 |
suse
|
high | CVE-2025-31115 severity important: SUSE including 377 source package names (0.0.17-1.1:liblzma5-5.4.1-150600.3.3.1, 0.1.6-1.2:liblzma5-5.4.1-150600.3.3.1, …), 958 product×package rows across 284 product lines (Container bci/gcc, Container bci/golang, … (284 product lines)): Fixed 603, Known Affected 231, Known Not Affected 124. | https://www.suse.com/security/cve/CVE-2025-31115/ |
ubuntu
|
medium | CVE-2025-31115 medium priority: Ubuntu including 1 source packages (xz-utils), 9 status rows across 9 suites (bionic, focal, jammy, noble, oracular, plucky, trusty, upstream, xenial): not-affected 5, released 4. | https://ubuntu.com/security/CVE-2025-31115 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||