CVE-2025-15570

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ckolivas:lrzip:*:*:*:*:*:*:*:*

History

06 May 2026, 22:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2026/05/msg00011.html -
References () https://vuldb.com/?submit.752595 - Third Party Advisory, VDB Entry, Exploit () https://vuldb.com/?submit.752595 - Exploit, Third Party Advisory, VDB Entry

29 Apr 2026, 01:00

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en ckolivas lrzip hasta la versión 0.651. Esto afecta a la función lzma_decompress_buf del archivo stream.c. Al realizar una manipulación, se produce un uso después de liberar. Atacar localmente es un requisito. El exploit se ha hecho público y podría ser utilizado. Se informó al proyecto del problema con antelación a través de un informe de incidencias, pero aún no ha respondido.

27 Feb 2026, 18:13

Type Values Removed Values Added
First Time Ckolivas lrzip
Ckolivas
CPE cpe:2.3:a:ckolivas:lrzip:*:*:*:*:*:*:*:*
References () https://github.com/ckolivas/lrzip/ - () https://github.com/ckolivas/lrzip/ - Product
References () https://github.com/ckolivas/lrzip/issues/262 - () https://github.com/ckolivas/lrzip/issues/262 - Exploit, Issue Tracking
References () https://github.com/user-attachments/files/21709004/PoC_UAF.zip - () https://github.com/user-attachments/files/21709004/PoC_UAF.zip - Exploit
References () https://vuldb.com/?ctiid.344926 - () https://vuldb.com/?ctiid.344926 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.344926 - () https://vuldb.com/?id.344926 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.752595 - () https://vuldb.com/?submit.752595 - Third Party Advisory, VDB Entry, Exploit

10 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 14:16

Updated : 2026-06-17 08:38


NVD link : CVE-2025-15570

Mitre link : CVE-2025-15570

CVE.ORG link : CVE-2025-15570


JSON object : View

Products Affected

ckolivas

  • lrzip
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-416

Use After Free