Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-70452

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.

A flaw was found in rsync. This vulnerability allows a remote attacker to bypass hostname-based access control rules. By inducing DNS resolution failures, the rsync daemon incorrectly skips deny rules, granting unauthorized access to restricted module file trees.

Отчет

This Important flaw in rsync allows remote attackers to bypass hostname-based access controls. By inducing DNS resolution failures, an attacker can circumvent hosts deny rules, potentially gaining unauthorized access to restricted rsync module file trees on systems configured with hostname-based access controls and exposed to untrusted networks.

Меры по смягчению последствий

To mitigate this issue, configure rsync to use IP-based access controls instead of hostname-based rules in rsyncd.conf. Alternatively, restrict network access to the rsync daemon using firewall rules to allow connections only from trusted IP addresses or networks. This limits exposure by preventing untrusted remote attackers from reaching the service and attempting to induce DNS resolution failures. If changes are made to rsyncd.conf, the rsync daemon may need to be restarted or reloaded for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncAffected
Red Hat Enterprise Linux 6rsyncNot affected
Red Hat Enterprise Linux 7rsyncAffected
Red Hat Enterprise Linux 8rsyncAffected
Red Hat Enterprise Linux 9rsyncAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-636
https://bugzilla.redhat.com/show_bug.cgi?id=2515386rsync: rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure

EPSS

Процентиль: 38%
0.00462
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
18 дней назад

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.

CVSS3: 7.4
nvd
18 дней назад

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.

CVSS3: 7.4
msrc
8 дней назад

rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure

CVSS3: 7.4
debian
18 дней назад

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerabili ...

suse-cvrf
11 дней назад

Security update for rsync

EPSS

Процентиль: 38%
0.00462
Низкий

7.4 High

CVSS3

Уязвимость CVE-2026-70452