Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-70455

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.

A denial-of-service flaw in rsync allows remote attackers to exhaust system memory and CPU. By sending requests using the --zt Zstandard compression alias, an attacker can bypass security directives and spawn an excessive number of worker threads.

Отчет

This Important rsync denial-of-service vulnerability allows remote, unauthenticated attackers to exhaust server resources. By using the --zt alias for Zstandard compression, attackers can bypass refuse options to spawn unlimited worker threads and disrupt the service. RHEL 9 and older versions are unaffected.

Меры по смягчению последствий

If the rsync daemon is unused, immediately disable rsyncd.service to eliminate the attack surface. For active deployments, restrict network access (TCP 873) strictly to trusted hosts using firewall rules. Do not rely on refuse options = compress-threads for protection, as the --zt alias bypasses this configuration. Network isolation is the most effective defense.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncAffected
Red Hat Enterprise Linux 6rsyncNot affected
Red Hat Enterprise Linux 7rsyncNot affected
Red Hat Enterprise Linux 8rsyncNot affected
Red Hat Enterprise Linux 9rsyncNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2515406rsync: rsync: Denial of Service via Zstandard compression thread exhaustion

EPSS

Процентиль: 39%
0.00479
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
18 дней назад

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.

CVSS3: 7.5
nvd
18 дней назад

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.

CVSS3: 7.5
msrc
8 дней назад

rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion

CVSS3: 7.5
debian
18 дней назад

rsync 3.4.2 before 3.5.0contains a denial of service vulnerability tha ...

suse-cvrf
11 дней назад

Security update for rsync

EPSS

Процентиль: 39%
0.00479
Низкий

7.5 High

CVSS3