Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_enterprise_linux_10:xz xz as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: xz | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:xz xz as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: xz | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:xz xz as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: xz | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:xz xz as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: xz | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_8:xz xz as a component of Red Hat JBoss Enterprise Application Platform 8 | not affected vulnerable code not present | no version stated vendor label: xz | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:xz-compat-libs xz-compat-libs as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: xz-compat-libs | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:xz-devel xz-devel as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: xz-devel | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_6:xz-devel xz-devel as a component of Red Hat Enterprise Linux 6 | not affected vulnerable code not present | no version stated vendor label: xz-devel | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:xz-devel xz-devel as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: xz-devel | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:xz-devel xz-devel as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: xz-devel | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:xz-devel xz-devel as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: xz-devel | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:xz-libs xz-libs as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: xz-libs | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_6:xz-libs xz-libs as a component of Red Hat Enterprise Linux 6 | not affected vulnerable code not present | no version stated vendor label: xz-libs | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:xz-libs xz-libs as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: xz-libs | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:xz-libs xz-libs as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: xz-libs | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:xz-libs xz-libs as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: xz-libs | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:xz-lzma-compat xz-lzma-compat as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: xz-lzma-compat | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_6:xz-lzma-compat xz-lzma-compat as a component of Red Hat Enterprise Linux 6 | not affected vulnerable code not present | no version stated vendor label: xz-lzma-compat | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:xz-lzma-compat xz-lzma-compat as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: xz-lzma-compat | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:xz-lzma-compat xz-lzma-compat as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: xz-lzma-compat | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:xz-lzma-compat xz-lzma-compat as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: xz-lzma-compat | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:xz.src xz.src as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: xz.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_6:xz.src xz.src as a component of Red Hat Enterprise Linux 6 | not affected vulnerable code not present | no version stated vendor label: xz.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:xz.src xz.src as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: xz.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:xz.src xz.src as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: xz.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:xz.src xz.src as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: xz.src | not applicable | csaf_redhat | |
| https://github.com/tukaani-project/xz | affected | >= 2d7d862e3ffa8cec4fd3fdffcd84e984a17aa429, <= fd1b975b7851e081ed6e5cf63df946cd5cbdbb94 | none available | osv | |
| //xz xz | affected | 5.6.0 | none available | cve_cna | |
| //xz xz | affected | 5.6.1 | none available | cve_cna | |
| Red Hat/Red Hat Enterprise Linux 10/xz Red Hat · Red Hat Enterprise Linux 10 | not affected | no version stated vendor label: all versions | not applicable | cve_cna | |
| Red Hat/Red Hat Enterprise Linux 6/xz Red Hat · Red Hat Enterprise Linux 6 | not affected | no version stated vendor label: all versions | not applicable | cve_cna | |
| Red Hat/Red Hat Enterprise Linux 7/xz Red Hat · Red Hat Enterprise Linux 7 | not affected | no version stated vendor label: all versions | not applicable | cve_cna | |
| Red Hat/Red Hat Enterprise Linux 8/xz Red Hat · Red Hat Enterprise Linux 8 | not affected | no version stated vendor label: all versions | not applicable | cve_cna | |
| Red Hat/Red Hat Enterprise Linux 9/xz Red Hat · Red Hat Enterprise Linux 9 | not affected | no version stated vendor label: all versions | not applicable | cve_cna | |
| Red Hat/Red Hat JBoss Enterprise Application Platform 8/xz Red Hat · Red Hat JBoss Enterprise Application Platform 8 | not affected | no version stated vendor label: all versions | not applicable | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.