PT-2026-71658 · Rsync · Rsync
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rsync versions 3.0.0 through 3.4.x
Description
An out-of-bounds write occurs when triggering HLINK BUMP processing on file entries that have the
FLAG HLINKED flag set while the hard-link preservation option is inactive. This happens because the file struct layout lacks the F SUM field, allowing memory access beyond the allocated structure and resulting in the corruption of adjacent heap or stack data.Recommendations
Update rsync to version 3.5.0 or later.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsync