Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21179-1

Опубликовано: 30 июн. 2026
Источник: suse-cvrf

Описание

Security update for lrzip

This update for lrzip fixes the following issues:

Changes in lrzip:

  • Update to version 0.660:
    • Do not clean up thread structures in decompression failure conditions, fixing a use-after-free in lzma_decompress_buf() and a NULL pointer dereference in ucompthread() on corrupt/malicious archives (CVE-2025-15570, boo#1258016; CVE-2025-15571, boo#1258023)
    • Handle -L given without a parameter, fixing a NULL pointer dereference (CVE-2025-9396, boo#1248598)
    • Add write bounds checking in libzpaq and sanity checks for maliciously encoded headers and oversized allocations
    • Various STDIO, portability and build fixes (OpenBSD support, non-x86 zpaq, autoconf warnings); drop Doxygen doc build

Список пакетов

openSUSE Leap 16.0
lrzip-0.660-bp160.1.1

Описание

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.


Затронутые продукты
openSUSE Leap 16.0:lrzip-0.660-bp160.1.1

Ссылки

Описание

A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.


Затронутые продукты
openSUSE Leap 16.0:lrzip-0.660-bp160.1.1

Ссылки

Описание

A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be exploited.


Затронутые продукты
openSUSE Leap 16.0:lrzip-0.660-bp160.1.1

Ссылки