Path Traversal in lrzsz Utility by Uwe Kleine-König
CVE-2026-105840

7.7HIGH

Key Information:

Vendor

Uwe Ohse

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105840?

The lrzsz utility, prior to version 0.13.0, suffers from a path traversal vulnerability in its lrz receive function. This flaw allows malicious ZMODEM senders to exploit the utility's restricted mode to write files outside the intended directory by using absolute pathnames. The issue arises from the checkpath() function in src/lrz.c, which only rejects '../' sequences unless compiled with the --enable-pubdir option. This enables attackers to send files with absolute paths, potentially overwriting any files that are writable by the receiving user, raising significant security concerns regarding file integrity.

Affected Version(s)

lrzsz 0 < 0.13.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.