Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41035

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

A flaw was found in rsync. When rsync is configured to handle extended attributes (using the -X or --xattrs option), a remote attacker can exploit a use-after-free vulnerability. This occurs because the receive_xattr function incorrectly processes an untrusted length value during a sorting operation, leading to memory corruption. Successful exploitation can result in a denial of service, causing the rsync process to crash, and may potentially allow for arbitrary code execution.

Отчет

This is an Important flaw in rsync that allows a remote attacker to cause a denial of service or potentially execute arbitrary code. The vulnerability is present when rsync is used with extended attributes enabled via the -X or --xattrs option, which is not a default configuration. Exploitation requires the victim to explicitly enable this feature.

Меры по смягчению последствий

To mitigate this vulnerability, avoid using the -X or --xattrs options with rsync if extended attribute handling is not essential for your operations. Disabling these options prevents the vulnerable code path from being exercised. This may impact functionality that relies on extended attributes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat Enterprise Linux 10rsyncFixedRHSA-2026:1915219.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportrsyncFixedRHSA-2026:2069626.05.2026
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONrsyncFixedRHSA-2026:2517311.06.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportrsyncFixedRHSA-2026:2517211.06.2026
Red Hat Enterprise Linux 8rsyncFixedRHSA-2026:1748114.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportrsyncFixedRHSA-2026:2517011.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnrsyncFixedRHSA-2026:2517011.06.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportrsyncFixedRHSA-2026:2519011.06.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnrsyncFixedRHSA-2026:2519011.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2458898rsync: Rsync: Use-after-free vulnerability in extended attribute handling

EPSS

Процентиль: 33%
0.00393
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
5 месяцев назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

CVSS3: 7.4
nvd
5 месяцев назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

CVSS3: 7.4
msrc
5 месяцев назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

CVSS3: 7.4
debian
5 месяцев назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted len ...

suse-cvrf
4 месяца назад

Security update for rsync

EPSS

Процентиль: 33%
0.00393
Низкий

7.4 High

CVSS3