Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-70456

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

EPSS

Процентиль: 33%
0.00396
Низкий

8.2 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.2
ubuntu
18 дней назад

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

CVSS3: 8.2
redhat
18 дней назад

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

CVSS3: 8.2
msrc
8 дней назад

rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()

CVSS3: 8.2
debian
18 дней назад

rsync 3.0.1 before 3.5.0contains an out-of-bounds write vulnerability ...

suse-cvrf
11 дней назад

Security update for rsync

EPSS

Процентиль: 33%
0.00396
Низкий

8.2 High

CVSS3

Дефекты

CWE-787