PT-2026-71662 · Rsync · Rsync

·

CVE-2026-70462

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rsync versions 3.1.0 through 3.4.x
Description A signed integer overflow exists in the I/O timeout implementation. An attacker can inject MSG IO TIMEOUT messages containing non-positive values (zero or negative), causing the timeout variable to wrap. This prevents the timeout check from triggering, allowing idle or stalled connections to occupy daemon slots indefinitely, which results in resource exhaustion.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Integer Overflow

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95840
CVE-2026-70462
ECHO-255D-4439-03D3
GHSA-J9WH-5JMP-2M64
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync