Threat reportVulnerabilityTL-2026-1001

XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact

highACTIVE

XZ Utils Multithreaded Decoder Race Condition (TL-2026-1001), also tracked as XZ Utils Multithreaded Decoder Bug, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-06-30. It has no confirmed attribution, affects Tukaani Project XZ Utils (liblzma), references 1 CVE (CVE-2025-31115), maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 31 indicators of compromise.

CVSS
7.5/10High
CVEs
1Referenced vulnerabilities
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
31Indicators of compromise

Key facts for TL-2026-1001

Threat ID
TL-2026-1001
Also known as
XZ Utils Multithreaded Decoder Bug, GHSA-6cc8-p5mm-29w2
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
critical-manufacturing, utilities, energy, water-wastewater, chemicals, food-beverage, automotive, pharmacy
Target regions
worldwide, europe, north-america, asia-pacific, middle-east
Detection rules
9
Indicators of compromise
31

Malware and tooling in XZ Utils Multithreaded Decoder Race Condition

Malware and tooling: Compressed file exploit payload, xz (command-line tool), xzdec

How XZ Utils Multithreaded Decoder Race Condition works

A critical race condition in XZ Utils 5.3.3alpha-5.8.0 multithreaded .xz decoder (liblzma lzma_stream_decoder_mt) causes heap use-after-free and null pointer dereference, enabling remote denial of service and memory corruption on industrial automation platforms. CVSS 7.5 (CVSS 4.0: 8.7 HIGH). Affects B&R Terminal OS and Siemens SIMATIC S7-1500 industrial controllers deployed worldwide.

XZ Utils is a lossless data compression library providing general-purpose data compression functionality and command-line tools. The vulnerability resides in the multithreaded .xz decoder implementation (liblzma library), specifically in the lzma_stream_decoder_mt function that handles parallel decompression of .xz format files. In affected versions (5.3.3alpha through 5.8.0), an invalid or maliciously crafted .xz input file can trigger a race condition in the multithreaded decoder, resulting in heap memory being freed prematurely during multi-threaded decompression operations. This leads to heap use-after-free (CWE-416) memory corruption and writes to addresses derived from null pointer dereference (CWE-476), potentially enabling arbitrary memory access patterns. The single-threaded .xz decoder (lzma_stream_decoder function) is NOT affected. The race condition occurs due to improper synchronization of thread-local memory management in the decoder's internal state machine, allowing one thread to free memory that another thread is still attempting to dereference. For industrial control systems like B&R Automation Terminal OS (T30, T50, T80, C50, C80, FT50, MT50, PPC3100 terminals) and Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP, this vulnerability poses a denial of service risk: an attacker who can inject or redirect .xz-compressed files to these devices (via network file services, firmware update channels, or log compression mechanisms) can cause the device to crash or enter an undefined state, disrupting industrial processes. The vulnerability was discovered by independent security researcher Harri K. Koskinen during routine fuzzing and analysis. The patch was backported to stable branches v5.4, v5.6, and v5.8, with a standalone patch file available for older releases. No exploitation in the wild has been reported as of June 2026, though the vulnerability remains unpatched in legacy industrial systems running older XZ Utils versions embedded in their firmware.

MITRE ATT&CK techniques used in TL-2026-1001

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information

exfiltration

T1041 Exfiltration Over C2 Channel

Discovery

T1082 System Information Discovery

Initial Access

T1195 Supply Chain Compromise; T1566 Phishing

Execution

T1203 Exploitation for Client Execution; T1204 User Execution

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1485 Data Destruction; T1490 Inhibit System Recovery; T1496 Resource Hijacking; T1529 System Shutdown/Reboot; T1531 Account Access Removal

Persistence

T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

defense-impairment

T1553 Subvert Trust Controls; T1601 Modify System Image

Affected products and versions in XZ Utils Multithreaded Decoder Race Condition

  • Tukaani Project — XZ Utils (liblzma)
    Vulnerable versions: 5.3.3alpha; 5.4.x; 5.5.x; 5.6.x; 5.7.x; 5.8.0
    Fixed in: 5.8.1+; v5.4 with patch; v5.6 with patch; v5.8 with patch
  • B&R Industrial Automation GmbH — Automation Terminal OS (PPC3100)
    Vulnerable versions: < 1.8.1
    Fixed in: 1.8.1+
  • B&R Industrial Automation GmbH — Automation Terminal OS (C50, C80)
    Vulnerable versions: < 1.8.0
    Fixed in: 1.8.0+
  • B&R Industrial Automation GmbH — Automation Terminal OS (T30, T80)
    Vulnerable versions: < 1.8.0
    Fixed in: 1.8.0+
  • B&R Industrial Automation GmbH — Automation Terminal OS (FT50, MT50, T50)
    Vulnerable versions: < 1.8.1
    Fixed in: 1.8.1+
  • Siemens — SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
    Vulnerable versions: V3.1.5
    Fixed in: Patch pending via SSA-082556
  • Siemens — SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
    Vulnerable versions: V3.1.5
    Fixed in: Patch pending via SSA-082556
  • Siemens — SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
    Vulnerable versions: V3.1.5
    Fixed in: Patch pending via SSA-082556

Remediation for XZ Utils Multithreaded Decoder Race Condition

Patches

  • XZ Utils 5.8.1 (mainline fix)
  • XZ Utils 5.8.3 (includes additional security fix)
  • Backported patches: v5.4.x, v5.6.x, v5.8.x branches
  • Standalone patch: xz-cve-2025-31115.patch from tukaani.org
  • B&R Terminal OS 1.8.0+ (C50, C80, T30, T80), 1.8.1+ (PPC3100, FT50, MT50, T50)
  • Siemens SSA-082556 firmware update

Immediate actions

  • Block or filter malicious .xz file uploads at network perimeter
  • Restrict access to firmware update channels and file services on ICS networks
  • Monitor industrial devices for unexpected crashes or error states
  • Isolate affected industrial controllers from untrusted networks
  • Implement signature-based detection for crafted .xz files with invalid stream headers

Workarounds

  • Disable multithreaded compression in ICS systems (use xz --decompress --threads=1 or xzdec binary for single-threaded operation)
  • Whitelist trusted .xz file sources; reject unexpected compressed files
  • Disable automatic firmware update mechanisms until patches applied
  • Use alternative compression formats (gzip, bzip2) instead of .xz for firmware updates

Longer-term hardening

  • Upgrade B&R Automation Terminal OS to firmware versions with XZ Utils >= 5.8.1 integration (PPC3100 1.8.1+, C50/C80/T30/T80 1.8.0+, FT50/MT50/T50 1.8.1+)
  • Upgrade Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP to patched firmware version (advisory SSA-082556)
  • Apply standalone CVE-2025-31115 patch to legacy XZ Utils builds
  • Deploy network segmentation: physically isolate ICS from business networks, require VPN/firewall rules for all remote access
  • Implement application-level integrity checking for critical file decompression operations
  • Upgrade to XZ Utils 5.8.3+ which includes additional security fixes
  • Maintain firmware version inventory to track unpatched legacy systems

CVEs associated with XZ Utils Multithreaded Decoder Race Condition

CVE-2025-31115

Weaknesses (CWE) in XZ Utils Multithreaded Decoder Race Condition

CWE-366, CWE-416, CWE-476, CWE-826

Timeline of XZ Utils Multithreaded Decoder Race Condition

  • Fix committed to XZ Utils repository branches: v5.4, v5.6, v5.8, and master; XZ Utils 5.8.1 released as primary fix version; standalone patch distributed via tukaani.org; affected function lzma_stream_decoder_mt corrected to prevent premature thread memory deallocation
  • CVE-2025-31115 publicly disclosed by XZ Utils maintainers on GitHub Security Advisory GHSA-6cc8-p5mm-29w2; vulnerability published on NVD with CVSS 3.1 score of 7.5 HIGH
  • Siemens Security Advisory SSA-082556 published identifying vulnerable SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP firmware V3.1.5; patch development announced; estimated impact on global Siemens industrial deployed base
  • 14 months post-disclosure: no active exploitation reported in CISA KEV database; however, security awareness among industrial automation administrators remains limited; vulnerability continues unpatched in legacy B&R and Siemens installations worldwide
  • XZ Utils 5.8.3 released with additional minor security issue fix affecting all stable releases; backport patches updated for v5.4 and v5.6 branches; recommendation to upgrade from 5.8.0/5.8.1 to 5.8.3
  • B&R Industrial Automation begins phased firmware distribution for Terminal OS updates incorporating XZ Utils fixes; Terminal OS 1.8.0 and 1.8.1 releases initiated; deployment constrained by legacy system compatibility concerns and industrial uptime windows
  • Siemens advisory SSA-082556 updated with revised mitigation status; firmware fix development ongoing for SIMATIC S7-1500 controllers; 14 months post-disclosure, patch still in development; customers advised to implement network segmentation as interim mitigation
  • NVD entry for CVE-2025-31115 updated with CVSS 4.0 score of 8.7 HIGH (increased from CVSS 3.1 7.5); vulnerability status remains 'Deferred' with updated severity assessment reflecting expanded threat landscape
  • As of current date, CVE-2025-31115 remains unpatched in deployed B&R and Siemens industrial systems globally; no active exploitation reported, but legacy firmware continues to ship with vulnerable XZ Utils; risk assessment: HIGH for ICS environments, MEDIUM for enterprise Linux systems
  • CISA issues ICS Advisory ICSA-26-181-05 detailing impact on B&R Industrial Automation products (PPC3100, C50, C80, FT50, MT50, T30, T80, T50 Terminal OS); multiple industrial device firmware versions identified as vulnerable; coordinated disclosure with industrial OEMs

Sources cited for XZ Utils Multithreaded Decoder Race Condition

Detection coverage for TL-2026-1001

As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1001 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
31 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats