Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-15570

Опубликовано: 10 фев. 2026
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lrzipfixed0.660-1package
lrzipno-dsatrixiepackage

Примечания

  • https://github.com/ckolivas/lrzip/issues/262

  • Fixed by: https://github.com/ckolivas/lrzip/commit/96931e7019c8cde6b5f2d3286a5470a67ed9a8f6 (v0.660)

EPSS

Процентиль: 11%
0.00209
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
7 месяцев назад

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 5.3
nvd
7 месяцев назад

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 5.3
github
7 месяцев назад

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

suse-cvrf
3 месяца назад

Security update for lrzip

EPSS

Процентиль: 11%
0.00209
Низкий