Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE Leap 16.0 lrzip Important Issues Fixed Advisory 2026-21179-1

opensuse
Calendar Grey July 1, 2026
Scroller Opensuse
Update for lrzip on openSUSE Leap 16.0 resolves important security issues and includes bug fixes. Act promptly!
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.

Description

This update for lrzip fixes the following issues:

Changes in lrzip:

- Update to version 0.660:

* Do not clean up thread structures in decompression failure

conditions, fixing a use-after-free in lzma_decompress_buf() and a

NULL pointer dereference in ucompthread() on corrupt/malicious

archives (CVE-2025-15570, boo#1258016; CVE-2025-15571, boo#1258023)

* Handle -L given without a parameter, fixing a NULL pointer

dereference (CVE-2025-9396, boo#1248598)

* Add write bounds checking in libzpaq and sanity checks for

maliciously encoded headers and oversized allocations

* Various STDIO, portability and build fixes (OpenBSD support,

non-x86 zpaq, autoconf warnings); drop Doxygen doc build

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

lrzip-0.660-bp160.1.1

References

* bsc#1248598

* bsc#1258016

* bsc#1258023

References:

* https://www.suse.com/security/cve/CVE-2025-15570.html

* https://www.suse.com/security/cve/CVE-2025-15571.html

* https://www.suse.com/security/cve/CVE-2025-9396.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21179-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.