Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-105840: lrzsz allows overwriting any writable file
CVE-2026-105840 · published 4 days ago
Summary
The lrzsz file‑transfer tool (versions before 0.13.0) can be tricked by a malicious sender into saving files to any location the receiving user can write to, not just the current folder. This happens because the program fails to block absolute path names when checking where to place incoming files. Update to the latest version of lrzsz or apply the vendor’s patch to stop this behavior.
What to do
- Update uwe ohse lrzsz to version 0.13.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | uwe ohse | lrzsz | < 0.13.0 |
| Debian:12 | debian | lrzsz | All versions |
| Ubuntu:14.04:LTS | canonical | lrzsz | All versions |
Original advisory text
lrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath()
lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files outside the current directory using absolute pathnames. Because checkpath() in src/lrz.c only rejects '../' sequences unless built with --enable-pubdir, attackers can send files named with absolute paths to overwrite any file writable by the receiving user.
References
- https://ubuntu.com/security/CVE-2026-105840 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-105840 Third Party Advisory
- https://ohse.de/uwe/software/lrzsz/NEWS-0.13.0.html
- https://ohse.de/uwe/software/lrzsz.html
- https://www.vulncheck.com/advisories/lrzsz-before-0.13.0-path-traversal-via-lrz-...
- https://security-tracker.debian.org/tracker/CVE-2026-105840 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.9
Critical
Type
CWE-22Path Traversal
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-105840 · NVD
CVE-2026-105840 · MITRE
DEBIAN-CVE-2026-105840 · OSV
UBUNTU-CVE-2026-105840 · OSV
Track software like this
Free during beta