CVE-2026-105842
Deferred Deferred - Pending Action

Heap Overflow in lrzsz Receive Utility

Vulnerability report for CVE-2026-105842, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulnCheck

Description

lrzsz before 0.13.0 contains a heap-based buffer overflow vulnerability in procheader() of the lrz receive utility when copying overlong sender-supplied filenames into Pathname. Malicious ZMODEM senders can supply filenames up to 8192 bytes, overflowing the buffer via sprintf() in pipe mode or strcpy() to corrupt heap memory and crash lrz.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Uwe Ohse lrzsz 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

lrzsz before version 0.13.0 has a heap-based buffer overflow in the procheader() function of the lrz receive utility. When receiving files via ZMODEM protocol, malicious senders can provide filenames up to 8192 bytes long. This overflows a buffer during copying, using sprintf() in pipe mode or strcpy(), corrupting heap memory and causing crashes.

Detection Guidance

Detecting this vulnerability requires checking for outdated versions of lrzsz. Run 'lrzsz --version' to see if your version is below 0.13.0. Inspect ZMODEM transfers for unusually long filenames, as malicious senders may exploit this to trigger the overflow.

Impact Analysis

An attacker could exploit this to crash the lrzsz utility during file transfers, potentially disrupting file transfer operations. If exploited in certain environments, it might allow arbitrary code execution, though this depends on system configurations and mitigations.

Mitigation Strategies

Upgrade lrzsz to version 0.13.0 or later immediately. Disable ZMODEM transfers if not required. Monitor network traffic for suspicious long filenames during file transfers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105842. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart