PT-2026-71630 · Rsync · Rsync
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.5.0
Description
An out-of-bounds read exists in the sender-side block matching logic. A malicious receiver can trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. This causes a negative offset calculation during delta computation, leading to an out-of-bounds read of file data buffer memory on the sender side.
Recommendations
Update rsync to version 3.5.0 or later.
Exploit
Fix
Improper Validation of Array Index
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rsync