| Release | Version |
|---|---|
| bullseye | 0.641-1+deb11u1 |
| bullseye (security) | 0.641-1+deb11u2 |
| bookworm | 0.651-2 |
| trixie | 0.651-3 |
| forky | 0.660-1 |
| sid | 0.660-1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2025-15571 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | fixed | fixed | A security vulnerability has been detected in ckolivas lrzip up to 0.6 ... |
| CVE-2025-15570 | fixed | vulnerable | vulnerable (no DSA) | fixed | fixed | A vulnerability was found in ckolivas lrzip up to 0.651. This impacts ... |
| CVE-2023-39741 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | fixed | lrzip v0.651 was discovered to contain a heap overflow via the libzpaq ... |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2025-9396 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | A security flaw has been discovered in ckolivas lrzip up to 0.651. Thi ... |
| CVE-2022-33067 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | Lrzip v0.651 was discovered to contain multiple invalid arithmetic shi ... |
| CVE-2021-33453 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An issue was discovered in lrzip version 0.641. There is a use-after-f ... |
| CVE-2021-33451 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An issue was discovered in lrzip version 0.641. There are memory leaks ... |
| CVE-2019-10654 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in ... |
| Bug | Description |
|---|---|
| CVE-2022-28044 | Irzip v0.640 was discovered to contain a heap memory corruption via th ... |
| CVE-2022-26291 | lrzip v0.641 was discovered to contain a multiple concurrency use-afte ... |
| CVE-2021-27347 | Use after free in lzma_decompress_buf function in stream.c in Irzip 0. ... |
| CVE-2021-27345 | A null pointer dereference was discovered in ucompthread in stream.c i ... |
| CVE-2020-25467 | A null pointer dereference was discovered lzo_decompress_buf in stream ... |
| CVE-2018-11496 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read ... |
| CVE-2018-10685 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ... |
| CVE-2018-9058 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the ... |
| CVE-2018-5786 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and app ... |
| CVE-2018-5747 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ... |
| CVE-2018-5650 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and app ... |
| CVE-2017-9929 | In lrzip 0.631, a stack buffer overflow was found in the function get_ ... |
| CVE-2017-9928 | In lrzip 0.631, a stack buffer overflow was found in the function get_ ... |
| CVE-2017-8847 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrz ... |
| CVE-2017-8846 | The read_stream function in stream.c in liblrzip.so in lrzip 0.631 all ... |
| CVE-2017-8845 | The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lr ... |
| CVE-2017-8844 | The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows ... |
| CVE-2017-8843 | The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 al ... |
| CVE-2017-8842 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrz ... |
| DSA / DLA | Description |
|---|---|
| DLA-4567-1 | lrzip - security update |
| DSA-5145-1 | lrzip - security update |
| DLA-3005-1 | lrzip - security update |
| DLA-2981-1 | lrzip - security update |
| DLA-2725-1 | lrzip - security update |