VDB
CVE-2025-9396
CVE-2025-9396
PUBLISHED
CVSS 1.7000000476837158 LOW
A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be exploited.
EPSS 0.27% · 18.4th percentile
Risk Scores
CVSS 2.0
1.7000000476837158
EPSS Score
0.27%
18.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ckolivas | lrzip | 0.651, 0 |
Timeline
- Aug 24, 2025 CVE Published
- Aug 25, 2025 EPSS Score
- Aug 25, 2025 PoC Published
- Aug 25, 2025 CVE Updated
- Sep 2, 2025 EPSS Score
- Sep 10, 2025 EPSS Score
- Sep 18, 2025 EPSS Score
- Sep 26, 2025 EPSS Score
- Oct 4, 2025 EPSS Score
- Oct 12, 2025 EPSS Score
- Oct 20, 2025 EPSS Score
- Oct 28, 2025 EPSS Score
References
- https://github.com/ckolivas/lrzip/issues/264 discussion
- VDB-321232 | ckolivas lrzip strtol_l.c __GI_____strtol_l_internal null pointer dereference vdb
- VDB-321232 | CTI Indicators (IOB, IOC, IOA) url
- https://drive.google.com/file/d/1EFbiiM1d7Ozb0ucZt6zRO3ngU8ugUnCn/view?usp=sharing exploit
- https://vuldb.com/?submit.632368 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-9396 advisory