Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-41035

Опубликовано: 16 апр. 2026
Источник: debian

Описание

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rsyncfixed3.4.2+ds1-1package
rsyncfixed3.4.1+ds1-5+deb13u2trixiepackage
rsyncfixed3.2.7-1+deb12u5bookwormpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/04/16/2

  • https://github.com/RsyncProject/rsync/issues/871

  • https://github.com/RsyncProject/rsync/pull/875

  • https://github.com/RsyncProject/rsync/commit/bb0a8118c2d2ab01140bac5e4e327e5e1ef90c9c (v3.4.2)

  • No security impact

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

CVSS3: 7.4
redhat
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

CVSS3: 7.4
nvd
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

msrc
4 месяца назад

Описание отсутствует

suse-cvrf
2 месяца назад

Security update for rsync