CVE-2026-105842
lrzsz before 0.13.0 Heap Buffer Overflow via lrz procheader() Pathname
CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th
lrzsz before 0.13.0 contains a heap-based buffer overflow vulnerability in procheader() of the lrz receive utility when copying overlong sender-supplied filenames into Pathname. Malicious ZMODEM senders can supply filenames up to 8192 bytes, overflowing the buffer via sprintf() in pipe mode or strcpy() to corrupt heap memory and crash lrz.
| CWE | CWE-122 |
| Vendor | uwe ohse |
| Product | lrzsz |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for uwe ohse lrzsz
Be the first to know when new medium vulnerabilities affecting uwe ohse lrzsz are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
Affected Versions
Uwe Ohse / lrzsz
0 < 0.13.0
References
Credits
Tristan Madani