CVE-2025-9396

Name
CVE-2025-9396
Description
A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be exploited.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
exploit https://drive.google.com/file/d/1EFbiiM1d7Ozb0ucZt6zRO3ngU8ugUnCn/view?usp=sharing
issue-tracking https://github.com/ckolivas/lrzip/issues/264
signature https://vuldb.com/?ctiid.321232
vdb-entry https://vuldb.com/?id.321232
third-party-advisory https://vuldb.com/?submit.632368

Match rules

CPE URI Source package Min version Max version
lrzip == 0.651 == 0.651
cpe:2.3:a:ckolivas:lrzip:*:*:*:*:*:*:*:* lrzip >= None <= 0.651

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
lrzip edge-community 0.651-r1 Roberto Oliveira <robertoguimaraes8@gmail.com> possibly vulnerable
lrzip 3.22-community 0.651-r1 Roberto Oliveira <robertoguimaraes8@gmail.com> possibly vulnerable