PT-2026-71630 · Rsync · Rsync

·

CVE-2026-53792

·

Published

2026-08-13

·

Updated

2026-08-26

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.5.0
Description An out-of-bounds read exists in the sender-side block matching logic. A malicious receiver can trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. This causes a negative offset calculation during delta computation, leading to an out-of-bounds read of file data buffer memory on the sender side.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Improper Validation of Array Index

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95786
CVE-2026-53792
ECHO-BF04-0160-41B5
GHSA-CG57-RP9G-56HW
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync