Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4567-1 | lrzip security update |
Wed, 06 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 27 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ckolivas:lrzip:*:*:*:*:*:*:*:* |
Tue, 10 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ckolivas
Ckolivas lrzip |
|
| Vendors & Products |
Ckolivas
Ckolivas lrzip |
Tue, 10 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 10 Feb 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | ckolivas lrzip stream.c lzma_decompress_buf use after free | |
| Weaknesses | CWE-119 CWE-416 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-06T21:25:28.267Z
Reserved: 2026-02-08T08:13:05.970Z
Link: CVE-2025-15570
Updated: 2026-05-06T21:25:28.267Z
Status : Modified
Published: 2026-02-10T14:16:07.667
Modified: 2026-05-06T22:16:24.813
Link: CVE-2025-15570
No data.
OpenCVE Enrichment
Updated: 2026-02-10T15:37:12Z
Debian DLA