PT-2026-71659 · Rsync · Rsync

·

CVE-2026-70459

·

Published

2026-08-13

·

Updated

2026-08-26

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rsync versions 3.0.0 through 3.4.x
Description A null pointer dereference occurs in the daemon child process. A remote attacker can cause the daemon to crash by sending a file list where the first entry is a dot entry not typed as a directory. The daemon processes the first file list entry as a directory structure pointer without verifying the entry type, leading to an invalid or uninitialized pointer dereference that terminates the client connection.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95831
CVE-2026-70459
ECHO-6D1C-53B2-C07C
GHSA-P4V4-QXW9-Q72M
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync