PT-2026-71656 · Rsync · Rsync

·

CVE-2026-70456

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rsync versions 3.0.1 through 3.4.x
Description An out-of-bounds write exists in the read args() function. A malicious sender can corrupt adjacent heap memory by providing a crafted argument list. This occurs when the argument count fills the argv allocation exactly, causing the trailing NULL terminator to be written beyond the allocation boundary.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95843
CVE-2026-70456
ECHO-D2F4-19EF-8603
GHSA-78JC-79JV-V6RW
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync