Logo
vulnerabilityCVE-2025-9396
Name
CVE-2025-9396
Source
NVD ( link)Debian ( link)
Description
A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be exploited.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
lrzip
Exploitable

Vulnerability Ratings#


1.9
CVSSv4
3.3
CVSSv31
5.5
CVSSv31
1.7
CVSSv2
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
buildroot
master
0.651
Exploitable