Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-15571

Опубликовано: 10 фев. 2026
Источник: debian
EPSS Низкий

Описание

A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lrzipfixed0.660-1package
lrzippostponedtrixiepackage
lrzippostponedbookwormpackage
lrzippostponedbullseyepackage

Примечания

  • https://github.com/ckolivas/lrzip/issues/263

EPSS

Процентиль: 6%
0.00164
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
7 месяцев назад

A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.3
nvd
7 месяцев назад

A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.3
github
7 месяцев назад

A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

suse-cvrf
3 месяца назад

Security update for lrzip

EPSS

Процентиль: 6%
0.00164
Низкий