CVE-2025-15570
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzmadecompressbuf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/ckolivas/lrzip/, https://vuldb.com/?ctiid.344926, https://vuldb.com/?id.344926, https://vuldb.com/?submit.752595, https://github.com/ckolivas/lrzip/issues/262, https://vuldb.com/?ctiid.344926, https://github.com/ckolivas/lrzip/issues/262, https://github.com/user-attachments/files/21709004/PoC_UAF.zip, https://vuldb.com/?submit.752595
