PT-2026-71658 · Rsync · Rsync

·

CVE-2026-70458

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rsync versions 3.0.0 through 3.4.x
Description An out-of-bounds write occurs when triggering HLINK BUMP processing on file entries that have the FLAG HLINKED flag set while the hard-link preservation option is inactive. This happens because the file struct layout lacks the F SUM field, allowing memory access beyond the allocated structure and resulting in the corruption of adjacent heap or stack data.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95759
CVE-2026-70458
ECHO-7D81-CB43-3188
GHSA-GG3M-4M9M-268H
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync