CVE-2025-9396: Ckolivas Lrzip

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be exploited.

Affected products

  • Ckolivas Lrzip: up to and including 0.651

Published 2025-08-24. Last modified 2026-06-17.