Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-70456

Опубликовано: 13 авг. 2026
Источник: debian

Описание

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rsyncfixed3.5.0+ds1-1package

Примечания

  • https://download.samba.org/pub/rsync/NEWS#3.5.0

Связанные уязвимости

CVSS3: 8.2
ubuntu
18 дней назад

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

CVSS3: 8.2
redhat
18 дней назад

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

CVSS3: 8.2
nvd
18 дней назад

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

CVSS3: 8.2
msrc
8 дней назад

rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()

suse-cvrf
11 дней назад

Security update for rsync