A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/ckolivas/lrzip/ | Product |
| https://github.com/ckolivas/lrzip/issues/263 | Exploit Issue Tracking |
| https://github.com/user-attachments/files/21726331/PoC_NPD.zip | Exploit |
| https://vuldb.com/?ctiid.344931 | Permissions Required VDB Entry |
| https://vuldb.com/?id.344931 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.752603 | Third Party Advisory VDB Entry |
Configurations
History
27 Feb 2026, 16:24
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ckolivas lrzip
Ckolivas |
|
| CPE | cpe:2.3:a:ckolivas:lrzip:*:*:*:*:*:*:*:* | |
| References | () https://github.com/ckolivas/lrzip/ - Product | |
| References | () https://github.com/ckolivas/lrzip/issues/263 - Exploit, Issue Tracking | |
| References | () https://github.com/user-attachments/files/21726331/PoC_NPD.zip - Exploit | |
| References | () https://vuldb.com/?ctiid.344931 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.344931 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.752603 - Third Party Advisory, VDB Entry |
10 Feb 2026, 15:22
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-10 15:16
Updated : 2026-02-27 16:24
NVD link : CVE-2025-15571
Mitre link : CVE-2025-15571
CVE.ORG link : CVE-2025-15571
JSON object : View
Products Affected
ckolivas
- lrzip
