Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53792

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side.

A flaw was found in rsync. A malicious receiver can exploit an out-of-bounds read vulnerability in the sender-side block matching logic. By sending a specially crafted checksum block with a length of zero, an attacker can trigger memory access before the start of an allocated buffer. This can lead to a denial of service on the sender side.

Отчет

A Moderate denial of service flaw exists in rsync, where a malicious receiver can trigger an out-of-bounds read on the sending system. This vulnerability requires the sender to connect to a specially crafted malicious rsync server, which can lead to service disruption of file synchronization operations.

Меры по смягчению последствий

Disable unused rsyncd services (systemctl disable --now rsyncd), and if actively serving files, restrict port 873 to trusted clients to prevent untrusted pull requests from crashing the daemon. When operating as a client, only push data (rsync src/ host:dst/) to fully trusted receivers, as the out-of-bounds read is triggered by the receiving end.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncFix deferred
Red Hat Enterprise Linux 6rsyncFix deferred
Red Hat Enterprise Linux 7rsyncFix deferred
Red Hat Enterprise Linux 8rsyncFix deferred
Red Hat Enterprise Linux 9rsyncFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-129
https://bugzilla.redhat.com/show_bug.cgi?id=2515397rsync: rsync: Denial of Service via out-of-bounds read with crafted checksum block

EPSS

Процентиль: 23%
0.00311
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
24 дня назад

rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side.

CVSS3: 6.5
nvd
24 дня назад

rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side.

msrc
14 дней назад

rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block

CVSS3: 6.5
debian
24 дня назад

rsyncbefore 3.5.0contains an out-of-bounds read vulnerability in the s ...

suse-cvrf
17 дней назад

Security update for rsync

EPSS

Процентиль: 23%
0.00311
Низкий

6.5 Medium

CVSS3