Unknown · Rsync Daemon · CVE-2026-70464
**Name of the Vulnerable Software and Affected Versions**
rsync daemon versions 2.0.0 through 3.4.9
**Description**
A denial of service issue exists that allows unauthenticated remote attackers to exhaust daemon connection slots. This is achieved by stalling the handshake process either before or after module selection to avoid triggering the I/O timeout. Attackers can maintain numerous simultaneous connections by trickling data at a minimum rate or stalling completely before module selection, where no timeout is applied, thereby preventing legitimate clients from accessing the service.
**Recommendations**
Update rsync daemon to version 3.5.0 or later.