---
id: CVE-2026-105842
title: >-
  lrzsz before 0.13.0 contains a heap-based buffer overflow vulnerability in
  procheader() of the lrz receive utility when copying overlong sender-supplied
  filenames into Pathname
summary: >-
  lrzsz before 0.13.0 contains a heap-based buffer overflow vulnerability in
  procheader() of the lrz receive utility when copying overlong sender-supplied
  filenames into Pathname. Malicious ZMODEM senders can supply filenames up to
  8192 by…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H'
cwe:
  - CWE-122
vendor: Uwe Ohse
product: lrzsz
affected:
  - lrzsz < 0.13.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T15:25:00.650'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105842'
references:
  - url: 'https://ohse.de/uwe/software/lrzsz.html'
    label: disclosure@vulncheck.com
  - url: 'https://ohse.de/uwe/software/lrzsz/NEWS-0.13.0.html'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/lrzsz-before-0.13.0-heap-buffer-overflow-via-lrz-procheader-pathname
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T14:00:19.148Z'
---

## Overview

lrzsz before 0.13.0 contains a heap-based buffer overflow vulnerability in procheader() of the lrz receive utility when copying overlong sender-supplied filenames into Pathname. Malicious ZMODEM senders can supply filenames up to 8192 bytes, overflowing the buffer via sprintf() in pipe mode or strcpy() to corrupt heap memory and crash lrz.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
