Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53794

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service.

A flaw was found in rsync. A logic error in the --max-alloc handling allows a remote attacker to disable memory allocation sanity checks by setting --max-alloc=0. This can lead to the receiver attempting unbounded memory allocations, potentially exhausting available memory and causing a denial of service.

Отчет

This vulnerability in rsync is rated as Important. A remote attacker can exploit a logic error in the --max-alloc handling by providing --max-alloc=0, which disables memory allocation sanity checks. This can lead to unbounded memory consumption on the receiving system, resulting in a denial of service without requiring authentication or user interaction. Red Hat systems using rsync, particularly in daemon mode or when processing untrusted data, are at risk.

Меры по смягчению последствий

Avoid using the --max-alloc=0 option in rsync configurations or command-line arguments. If rsync is operating as a daemon, ensure that its configuration does not include --max-alloc=0. For rsync clients, refrain from using --max-alloc=0 when synchronizing with untrusted sources. This mitigation prevents the disabling of memory allocation sanity checks, thereby avoiding unbounded memory consumption. If rsync is running as a service, a restart may be required for configuration changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncFix deferred
Red Hat Enterprise Linux 6rsyncNot affected
Red Hat Enterprise Linux 7rsyncNot affected
Red Hat Enterprise Linux 8rsyncNot affected
Red Hat Enterprise Linux 9rsyncFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2515388rsync: rsync: Denial of Service via --max-alloc=0 logic error

EPSS

Процентиль: 30%
0.00372
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
24 дня назад

rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service.

CVSS3: 5.3
nvd
24 дня назад

rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service.

msrc
14 дней назад

rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error

CVSS3: 5.3
debian
24 дня назад

rsync before 3.5.0contains a logic error in --max-alloc handling that ...

suse-cvrf
17 дней назад

Security update for rsync

EPSS

Процентиль: 30%
0.00372
Низкий

5.3 Medium

CVSS3