Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.7

CVE-2026-105841: lrzsz allows remote command execution via crafted filenames

CVE-2026-105841 · published 4 days ago
Summary

The lrzsz file transfer tool (versions before 0.13.0) can run arbitrary commands when a malicious sender includes specially crafted filenames. This could let an attacker execute code on the receiving system with the user's privileges. Upgrade to version 0.13.0 or later, or apply the vendor's patch, and limit the use of lrzsz to trusted sources.

What to do
  • Update uwe ohse lrzsz to version 0.13.0 or later.
Affected software
Ecosystem VendorProductAffected versions
– uwe ohse lrzsz < 0.13.0
Debian:12 debian lrzsz All versions
Ubuntu:14.04:LTS canonical lrzsz All versions
Original advisory text
DEBIAN-CVE-2026-105841
lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by supplying crafted filenames. When lrz runs under a suffixed name such as lrztar, procheader() in src/lrz.c passes the unescaped ZMODEM/YMODEM filename to popen(), so shell metacharacters execute as the receiving user.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
7.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta