Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45232

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.

A flaw was found in rsync. A network attacker can exploit an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function by sending a malformed HTTP proxy response. This occurs when the RSYNC_PROXY environment variable is set and the attacker sends a response line of 1023 or more bytes without a newline terminator. This can corrupt stack memory, potentially leading to a Denial of Service (DoS).

Меры по смягчению последствий

To mitigate this issue, ensure that the RSYNC_PROXY environment variable is not set. If rsync is configured to use an HTTP proxy via this variable, unsetting it will prevent exploitation. To unset the RSYNC_PROXY environment variable for the current session, use: unset RSYNC_PROXY. For a more permanent solution, ensure that RSYNC_PROXY is not defined in system-wide or user-specific environment configuration files. Note that this mitigation will disable rsync's ability to use an HTTP proxy, which may impact functionality if proxy usage is required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncFix deferred
Red Hat Enterprise Linux 6rsyncFix deferred
Red Hat Enterprise Linux 7rsyncFix deferred
Red Hat Enterprise Linux 8rsyncFix deferred
Red Hat Enterprise Linux 9rsyncFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=2480057rsync: Rsync: Denial of Service via malformed HTTP proxy response

EPSS

Процентиль: 26%
0.00337
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
3 месяца назад

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.

CVSS3: 3.1
nvd
3 месяца назад

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.

CVSS3: 3.1
msrc
3 месяца назад

Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy

CVSS3: 3.1
debian
3 месяца назад

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack ...

suse-cvrf
2 месяца назад

Security update for rsync

EPSS

Процентиль: 26%
0.00337
Низкий

5.9 Medium

CVSS3