Updated lrzip package fixes security vulnerabilities
Publication date: 24 Jul 2026Modification date: 24 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2025-15570 , CVE-2025-9396
Description
The updated package fixes security vulnerabilities:
ckolivas lrzip stream.c lzma_decompress_buf use after free.
(CVE-2025-15570)
ckolivas lrzip strtol_l.c __GI_____strtol_l_internal null pointer
dereference. (CVE-2025-9396)
References
- https://bugs.mageia.org/show_bug.cgi?id=35760
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/JSNIFYQRLND7PULS3ODEDTISSERCMKIQ/
- https://github.com/ckolivas/lrzip/issues/262
- https://github.com/ckolivas/lrzip/issues/264
- https://www.cve.org/CVERecord?id=CVE-2025-15570
- https://www.cve.org/CVERecord?id=CVE-2025-9396
SRPMS
10/core
- lrzip-0.660-1.mga10