# XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact

> A critical race condition in XZ Utils 5.3.3alpha-5.8.0 multithreaded .xz decoder (liblzma lzma_stream_decoder_mt) causes heap use-after-free and null pointer dereference, enabling remote denial of service and memory corruption on industrial automation platforms. CVSS 7.5 (CVSS 4.0: 8.7 HIGH). Affects B&R Terminal OS and Siemens SIMATIC S7-1500 industrial controllers deployed worldwide.

- **Published:** 2026-06-30T16:30:00Z
- **Last reviewed:** 2026-06-30T16:30:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1001
- **ID:** TL-2026-1001
- **Severity:** HIGH (CVSS 7.5)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 31 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-31115

## Description

XZ Utils is a lossless data compression library providing general-purpose data compression functionality and command-line tools. The vulnerability resides in the multithreaded .xz decoder implementation (liblzma library), specifically in the lzma_stream_decoder_mt function that handles parallel decompression of .xz format files. In affected versions (5.3.3alpha through 5.8.0), an invalid or maliciously crafted .xz input file can trigger a race condition in the multithreaded decoder, resulting in heap memory being freed prematurely during multi-threaded decompression operations. This leads to heap use-after-free (CWE-416) memory corruption and writes to addresses derived from null pointer dereference (CWE-476), potentially enabling arbitrary memory access patterns. The single-threaded .xz decoder (lzma_stream_decoder function) is NOT affected. The race condition occurs due to improper synchronization of thread-local memory management in the decoder's internal state machine, allowing one thread to free memory that another thread is still attempting to dereference. For industrial control systems like B&R Automation Terminal OS (T30, T50, T80, C50, C80, FT50, MT50, PPC3100 terminals) and Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP, this vulnerability poses a denial of service risk: an attacker who can inject or redirect .xz-compressed files to these devices (via network file services, firmware update channels, or log compression mechanisms) can cause the device to crash or enter an undefined state, disrupting industrial processes. The vulnerability was discovered by independent security researcher Harri K. Koskinen during routine fuzzing and analysis. The patch was backported to stable branches v5.4, v5.6, and v5.8, with a standalone patch file available for older releases. No exploitation in the wild has been reported as of June 2026, though the vulnerability remains unpatched in legacy industrial systems running older XZ Utils versions embedded in their firmware.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1203 Exploitation for Client Execution
- T1531 Account Access Removal
- T1496 Resource Hijacking
- T1548 Abuse Elevation Control Mechanism
- T1027 Obfuscated Files or Information
- T1485 Data Destruction
- T1490 Inhibit System Recovery
- T1204 User Execution
- T1566 Phishing
- T1601 Modify System Image
- T1529 System Shutdown/Reboot
- T1082 System Information Discovery
- T1210 Exploitation of Remote Services
- T1041 Exfiltration Over C2 Channel
- T1005 Data from Local System
- T1553 Subvert Trust Controls
- T1547 Boot or Logon Autostart Execution

## Sources

- [CISA ICS Advisory ICSA-26-181-05](https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-05)
- [Siemens Security Advisory SSA-082556](https://cert-portal.siemens.com/productcert/html/ssa-082556.html)
- [GitHub Security Advisory GHSA-6cc8-p5mm-29w2](https://github.com/tukaani-project/xz/security/advisories/GHSA-6cc8-p5mm-29w2)
- [CVE-2025-31115 National Vulnerability Database](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-31115)
- [XZ Utils Security Advisory - CVE-2025-31115](https://tukaani.org/xz/)
- [XZ Utils Technical Deep Dive - Threaded Decoder Bug](https://tukaani.org/xz/threaded-decoder-early-free.html)
- [XZ Utils CVE-2025-31115 Patch File](https://tukaani.org/xz/xz-cve-2025-31115.patch)
- [GitHub Commit - XZ Utils Multithreaded Decoder Fix](https://github.com/tukaani-project/xz/commit/d5a2ffe41bb77b918a8c96084885d4dbe4bf6480)
- [OSS-Fuzz Discussion - XZ Utils Vulnerability Discovery](http://www.openwall.com/lists/oss-security/2025/04/03/1)
- [B&R Industrial Automation Security Bulletins](https://www.br-automation.com/en/downloads/security/)
- [XZ Utils Release Notes and Security History](https://github.com/tukaani-project/xz/releases)
- [CISA Known Exploited Vulnerabilities (KEV) Database](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [NVD CVSS v4.0 Scoring Update for CVE-2025-31115](https://nvd.nist.gov/vuln/detail/CVE-2025-31115)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1001
