CVE-2025-15570

Source
https://cve.org/CVERecord?id=CVE-2025-15570
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15570.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15570
Downstream
Published
2026-02-10T14:16:07.667Z
Modified
2026-04-10T05:23:02.463852Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzmadecompressbuf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

References

Affected packages

Git / github.com/ckolivas/lrzip

Affected ranges

Type
GIT
Repo
https://github.com/ckolivas/lrzip
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.651"
        }
    ]
}

Affected versions

v0.*
v0.45
v0.46
v0.47
v0.5
v0.5.1
v0.5.2
v0.520
v0.530
v0.540
v0.541
v0.542
v0.543
v0.544
v0.550
v0.551
v0.552
v0.560
v0.570
v0.600
v0.601
v0.602
v0.603
v0.604
v0.605
v0.606
v0.607
v0.608
v0.610
v0.611
v0.612
v0.613
v0.614
v0.615
v0.616
v0.620
v0.621
v0.630
v0.631
v0.640
v0.641
v0.650
v0.651

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15570.json"