CVE-2026-105841: lrzsz before 0.13.0 OS Command Injection via lrz Pipe Mode
lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by supplying crafted filenames. When lrz runs under a suffixed name such as lrztar, procheader() in src/lrz.c passes the unescaped ZMODEM/YMODEM filename to popen(), so shell metacharacters execute as the receiving user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
lrzszto a version that resolves this vulnerability.Fixed in 0.13.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments are exposed when the lrz receive utility is run in pipe mode under a suffixed name, such as lrztar, and receives files from remote ZMODEM or YMODEM senders. The injected command runs with the privileges of the receiving user.
What does an attacker need to exploit this issue?
An attacker needs to act as a remote sender and provide a crafted transfer filename containing shell metacharacters. The supplied CVSS vector indicates no attacker privileges are required, but user interaction is required and attack complexity is high.
How can I determine whether a system is affected?
Check whether the installed lrzsz version is earlier than 0.13.0, and whether lrz is invoked under a suffixed name for pipe-mode receiving, such as lrztar.