PT-2026-71664 · Unknown · Rsync Daemon
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
rsync daemon versions 2.0.0 through 3.4.9
Description
A denial of service issue exists that allows unauthenticated remote attackers to exhaust daemon connection slots. This is achieved by stalling the handshake process either before or after module selection to avoid triggering the I/O timeout. Attackers can maintain numerous simultaneous connections by trickling data at a minimum rate or stalling completely before module selection, where no timeout is applied, thereby preventing legitimate clients from accessing the service.
Recommendations
Update rsync daemon to version 3.5.0 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsync Daemon