Path Traversal in lrzsz Utility by Uwe Kleine-König
CVE-2026-105840
7.7HIGH
What is CVE-2026-105840?
The lrzsz utility, prior to version 0.13.0, suffers from a path traversal vulnerability in its lrz receive function. This flaw allows malicious ZMODEM senders to exploit the utility's restricted mode to write files outside the intended directory by using absolute pathnames. The issue arises from the checkpath() function in src/lrz.c, which only rejects '../' sequences unless compiled with the --enable-pubdir option. This enables attackers to send files with absolute paths, potentially overwriting any files that are writable by the receiving user, raising significant security concerns regarding file integrity.
Affected Version(s)
lrzsz 0 < 0.13.0
