Sceawere

Vulnerability Detail

CVE-2026-105842UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

lrzsz Heap Buffer Overflow

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
11h ago
Vendor
Uwe Ohse
Product
lrzsz
Attack Type
Heap-based Buffer Overflow
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H
Attack Complexity
HIGH

Narrative and Response

Description

lrzsz before 0.13.0 contains a heap-based buffer overflow vulnerability in procheader() of the lrz receive utility when copying overlong sender-supplied filenames into Pathname. Malicious ZMODEM senders can supply filenames up to 8192 bytes, overflowing the buffer via sprintf() in pipe mode or strcpy() to corrupt heap memory and crash lrz.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-06T14:17:41.620Z",
  "pubdate": "2026-10-06T14:17:41.620Z",
  "executiveSummary": "lrzsz versions prior to 0.13.0 are susceptible to a heap-based buffer overflow vulnerability residing within the procheader() function of the lrz utility.\nThe vulnerability is triggered during the processing of ZMODEM file transfers when a malicious sender provides an excessively long filename, exceeding the allocated buffer capacity of the Pathname variable.\nThis flaw allows an attacker to corrupt heap memory, potentially resulting in a denial-of-service condition through application crashes or, theoretically, arbitrary code execution.\nExploitation requires the attacker to act as a malicious ZMODEM sender, establishing a connection with a vulnerable lrz instance. There are no authentication requirements for this interaction as the protocol is designed to handle file transfers from remote entities.\nThe risk is significant due to the nature of file transfer utilities which are often used in automated processes or by users interacting with untrusted remote systems.\nThe impact includes service instability and potential system compromise if heap corruption primitives are leveraged to redirect control flow.",
  "technicalDetails": "The vulnerability originates in the procheader() function, which is responsible for parsing ZMODEM headers, specifically the file metadata including the filename. The implementation fails to enforce strict bounds checking when copying sender-supplied filename data into a fixed-size heap-allocated buffer identified as Pathname.\nThe ZMODEM protocol supports filenames up to 8192 bytes. In the vulnerable lrzsz implementation, the receiving function does not validate that the incoming filename length conforms to the limitations of the destination buffer. Consequently, when the application executes operations such as sprintf() (in pipe mode) or strcpy(), the length of the supplied filename exceeds the allocated heap space for Pathname, triggering an out-of-bounds write.\nThe attack flow begins when a remote malicious ZMODEM sender initiates a file transfer request. The sender crafts a ZMODEM header containing a malicious filename payload that exceeds the capacity of the internal buffer. When lrz receives this header, procheader() is invoked to process the data.\nBecause the buffer is located on the heap, the overflow overwrites adjacent heap metadata or application-specific structures. If an attacker carefully crafts the overflowing payload, they can manipulate heap chunks, potentially overwriting function pointers or object headers. This manipulation can lead to immediate process termination (segmentation fault) or, if the heap layout is predictable, provide a path for memory corruption exploitation.\nThe vulnerability is restricted to the lrz receive utility, but because lrz is often invoked automatically when a terminal session receives ZMODEM escape sequences, the attack surface includes users simply interacting with remote systems via susceptible terminal emulators or serial connections. No elevated privileges are strictly required for the initial trigger, as the impact is confined to the user space of the process executing lrz.\nThe root cause is a classic improper boundary check (CWE-122: Heap-based Buffer Overflow). The lack of input length validation prior to performing memory copy operations allows for the corruption of the heap memory heap management structures or adjacent program data.\nPost-exploitation, the primary impact observed is a crash of the lrz process, effectively stopping the file transfer service and causing a denial-of-service. Advanced exploitation could theoretically result in remote code execution depending on the specific heap management implementation of the underlying system and the ability of an attacker to control the contents of the overflow."
}
CVE-2026-105842: lrzsz Heap Buffer Overflow (MEDIUM Severity, CVSS: 6.4) | Sceawere