Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-105840: lrzsz allows overwriting any writable file

CVE-2026-105840 · published 4 days ago
Summary

The lrzsz file‑transfer tool (versions before 0.13.0) can be tricked by a malicious sender into saving files to any location the receiving user can write to, not just the current folder. This happens because the program fails to block absolute path names when checking where to place incoming files. Update to the latest version of lrzsz or apply the vendor’s patch to stop this behavior.

What to do
  • Update uwe ohse lrzsz to version 0.13.0 or later.
Affected software
Ecosystem VendorProductAffected versions
– uwe ohse lrzsz < 0.13.0
Debian:12 debian lrzsz All versions
Ubuntu:14.04:LTS canonical lrzsz All versions
Original advisory text
lrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath()
lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files outside the current directory using absolute pathnames. Because checkpath() in src/lrz.c only rejects '../' sequences unless built with --enable-pubdir, attackers can send files named with absolute paths to overwrite any file writable by the receiving user.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta