{"id":"openSUSE-SU-2026:21179-1","summary":"Security update for lrzip","details":"This update for lrzip fixes the following issues:\n\nChanges in lrzip:\n\n- Update to version 0.660:\n  * Do not clean up thread structures in decompression failure\n    conditions, fixing a use-after-free in lzma_decompress_buf() and a\n    NULL pointer dereference in ucompthread() on corrupt/malicious\n    archives (CVE-2025-15570, boo#1258016; CVE-2025-15571, boo#1258023)\n  * Handle -L given without a parameter, fixing a NULL pointer\n    dereference (CVE-2025-9396, boo#1248598)\n  * Add write bounds checking in libzpaq and sanity checks for\n    maliciously encoded headers and oversized allocations\n  * Various STDIO, portability and build fixes (OpenBSD support,\n    non-x86 zpaq, autoconf warnings); drop Doxygen doc build\n","modified":"2026-07-02T18:24:18.175989238Z","published":"2026-06-30T11:29:53Z","related":["CVE-2025-15570","CVE-2025-15571","CVE-2025-9396"],"upstream":["CVE-2025-15570","CVE-2025-15571","CVE-2025-9396"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248598"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258016"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-15570"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-15571"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-9396"}],"affected":[{"package":{"name":"lrzip","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/lrzip&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.660-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"lrzip":"0.660-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21179-1.json"}}],"schema_version":"1.7.5"}