CVE-2025-15571

Source
https://cve.org/CVERecord?id=CVE-2025-15571
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15571.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15571
Downstream
Related
Published
2026-02-10T14:32:08.345Z
Modified
2026-07-15T01:49:15.939279688Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
ckolivas lrzip stream.c ucompthread null pointer dereference
Details

A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15571.json",
    "cwe_ids": [
        "CWE-404",
        "CWE-476"
    ]
}
References

Affected packages

Git / github.com/ckolivas/lrzip

Affected ranges

Type
GIT
Repo
https://github.com/ckolivas/lrzip
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0.651"
        },
        {
            "last_affected": "0.651"
        },
        {
            "introduced": "0"
        }
    ],
    "cpe": "cpe:2.3:a:ckolivas:lrzip:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

0.*
0.651
v0.*
v0.651

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15571.json"