PT-2026-71664 · Unknown · Rsync Daemon

·

CVE-2026-70464

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rsync daemon versions 2.0.0 through 3.4.9
Description A denial of service issue exists that allows unauthenticated remote attackers to exhaust daemon connection slots. This is achieved by stalling the handshake process either before or after module selection to avoid triggering the I/O timeout. Attackers can maintain numerous simultaneous connections by trickling data at a minimum rate or stalling completely before module selection, where no timeout is applied, thereby preventing legitimate clients from accessing the service.
Recommendations Update rsync daemon to version 3.5.0 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95792
CVE-2026-70464
ECHO-3879-0D40-E19E
GHSA-HRWQ-CCF7-RW5M
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync Daemon