CVE-2025-15570: Ckolivas Lrzip
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
- Ckolivas Lrzip: up to and including 0.651
Published 2026-02-10. Last modified 2026-06-17.