AZL-106667

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106667.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106667
Upstream
  • CVE-2026-105840
Published
2026-10-06T14:17:41Z
Modified
2026-10-07T14:17:12Z
Summary
CVE-2026-105840 affecting package lrzsz 0.12.20-50
Details

lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files outside the current directory using absolute pathnames. Because checkpath() in src/lrz.c only rejects '../' sequences unless built with --enable-pubdir, attackers can send files named with absolute paths to overwrite any file writable by the receiving user.

References

Affected packages

Azure Linux:3 / lrzsz

Package

Name
lrzsz
Purl
pkg:rpm/azure-linux/lrzsz

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.12.20-50

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106667.json"