Low severity3.3NVD Advisory· Published Aug 24, 2025· Updated Jun 17, 2026
CVE-2025-9396
CVE-2025-9396
Description
A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be exploited.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/lrzip&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/lrzip&distro=openSUSE%20Tumbleweed
< 0.660-bp160.1.1+ 1 more
- (no CPE)range: < 0.660-bp160.1.1
- (no CPE)range: < 0.660-1.1
Patches
Vulnerability mechanics
References
5- drive.google.com/file/d/1EFbiiM1d7Ozb0ucZt6zRO3ngU8ugUnCn/viewnvdExploit
- github.com/ckolivas/lrzip/issues/264nvdExploitIssue TrackingVendor Advisory
- vuldb.comnvdExploitThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.