Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 459
Alerts This Week
Warning Icon 1 459

Mageia 10 lrzip Critical Use After Free Null Pointer Vulnerabilities

mageia
Calendar Grey July 23, 2026
Scroller Mageia
Mageia security update addresses critical issues in lrzip including use after free and null pointer dereference vulnerabilities.
Mageia 10 has released an update to address security vulnerabilities in lrzip, specifically a use-after-free bug and null pointer dereference, identified as CVE-2025-15570 and CVE-...

Summary

Description: The updated package fixes security vulnerabilities: ckolivas lrzip stream.c lzma_decompress_buf use after free. (CVE-2025-15570) ckolivas lrzip strtol_l.c __GI_____strtol_l_internal null pointer dereference. (CVE-2025-9396)

References

- https://bugs.mageia.org/show_bug.cgi?id=35760

- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/JSNIFYQRLND7PULS3ODEDTISSERCMKIQ/

- https://github.com/ckolivas/lrzip/issues/262

- https://github.com/ckolivas/lrzip/issues/264

- https://www.cve.org/CVERecord?id=CVE-2025-15570

- https://www.cve.org/CVERecord?id=CVE-2025-9396

Resolution

SRPMS

- 10/core/lrzip-0.660-1.mga10

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 24 Jul 2026 
URL: https://advisories.mageia.org/MGASA-2026-0292.html
Type: security
CVE: CVE-2025-15570, CVE-2025-9396

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.