Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-70459

Опубликовано: 13 авг. 2026
Источник: debian

Описание

rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rsyncfixed3.5.0+ds1-1package

Примечания

  • https://download.samba.org/pub/rsync/NEWS#3.5.0

Связанные уязвимости

CVSS3: 5.3
ubuntu
18 дней назад

rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection.

CVSS3: 5.3
nvd
18 дней назад

rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection.

CVSS3: 5.3
msrc
8 дней назад

rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry

suse-cvrf
11 дней назад

Security update for rsync

suse-cvrf
14 дней назад

Security update for rsync