Medium severity5.3NVD Advisory· Published Feb 10, 2026· Updated May 6, 2026
CVE-2025-15570
CVE-2025-15570
Description
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/ckolivas/lrzip/issues/262nvdExploitIssue Tracking
- vuldb.comnvdExploitThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
- lists.debian.org/debian-lts-announce/2026/05/msg00011.htmlnvd
News mentions
0No linked articles in our index yet.