PT-2026-71662 · Rsync · Rsync
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
rsync versions 3.1.0 through 3.4.x
Description
A signed integer overflow exists in the I/O timeout implementation. An attacker can inject
MSG IO TIMEOUT messages containing non-positive values (zero or negative), causing the timeout variable to wrap. This prevents the timeout check from triggering, allowing idle or stalled connections to occupy daemon slots indefinitely, which results in resource exhaustion.Recommendations
Update rsync to version 3.5.0 or later.
Exploit
Fix
Integer Overflow
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rsync