Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-70453

Опубликовано: 13 авг. 2026
Источник: debian
EPSS Низкий

Описание

rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rsyncfixed3.5.0+ds1-1package

Примечания

  • https://download.samba.org/pub/rsync/NEWS#3.5.0

EPSS

Процентиль: 42%
0.00525
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
18 дней назад

rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.

CVSS3: 6.5
redhat
18 дней назад

rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.

CVSS3: 7.5
nvd
18 дней назад

rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.

msrc
8 дней назад

rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()

suse-cvrf
11 дней назад

Security update for rsync

EPSS

Процентиль: 42%
0.00525
Низкий