Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.7
CVE-2026-105841: lrzsz allows remote command execution via crafted filenames
CVE-2026-105841 · published 4 days ago
Summary
The lrzsz file transfer tool (versions before 0.13.0) can run arbitrary commands when a malicious sender includes specially crafted filenames. This could let an attacker execute code on the receiving system with the user's privileges. Upgrade to version 0.13.0 or later, or apply the vendor's patch, and limit the use of lrzsz to trusted sources.
What to do
- Update uwe ohse lrzsz to version 0.13.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | uwe ohse | lrzsz | < 0.13.0 |
| Debian:12 | debian | lrzsz | All versions |
| Ubuntu:14.04:LTS | canonical | lrzsz | All versions |
Original advisory text
DEBIAN-CVE-2026-105841
lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by supplying crafted filenames. When lrz runs under a suffixed name such as lrztar, procheader() in src/lrz.c passes the unescaped ZMODEM/YMODEM filename to popen(), so shell metacharacters execute as the receiving user.
References
- https://ubuntu.com/security/CVE-2026-105841 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-105841 Third Party Advisory
- https://ohse.de/uwe/software/lrzsz/NEWS-0.13.0.html
- https://ohse.de/uwe/software/lrzsz.html
- https://www.vulncheck.com/advisories/lrzsz-before-0.13.0-os-command-injection-vi...
- https://security-tracker.debian.org/tracker/CVE-2026-105841 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
7.7
High
Type
CWE-78OS Command Injection
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-105841 · NVD
CVE-2026-105841 · MITRE
DEBIAN-CVE-2026-105841 · OSV
UBUNTU-CVE-2026-105841 · OSV
Track software like this
Free during beta