Medium severity5.3NVD Advisory· Published Feb 10, 2026· Updated Jun 17, 2026
CVE-2025-15570
CVE-2025-15570
Description
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/lrzip&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/lrzip&distro=openSUSE%20Tumbleweed
< 0.660-bp160.1.1+ 1 more
- (no CPE)range: < 0.660-bp160.1.1
- (no CPE)range: < 0.660-1.1
Patches
Vulnerability mechanics
References
5- github.com/ckolivas/lrzip/issues/262nvdExploitIssue Tracking
- vuldb.comnvdExploitThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
- lists.debian.org/debian-lts-announce/2026/05/msg00011.htmlnvd
News mentions
0No linked articles in our index yet.