Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-70461

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.

A flaw was found in rsync. Remote unauthenticated attackers can exploit a heap out-of-bounds write vulnerability by supplying a crafted files-from entry. This entry, containing both an interior and trailing backslash, causes the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer. This can lead to information disclosure or denial of service.

Отчет

This is an Important vulnerability in rsync that allows remote unauthenticated attackers to achieve information disclosure and denial of service. The flaw occurs in the rsync daemon when processing a specially crafted files-from entry, leading to a heap out-of-bounds write. This can be exploited against read-only rsync daemon modules, making it a significant risk for publicly exposed rsync services.

Меры по смягчению последствий

Restrict access to the rsync daemon (TCP 873) to trusted hosts with firewall rules. If the daemon is unused, disable and stop rsyncd.service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncAffected
Red Hat Enterprise Linux 6rsyncNot affected
Red Hat Enterprise Linux 7rsyncAffected
Red Hat Enterprise Linux 8rsyncAffected
Red Hat Enterprise Linux 9rsyncAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2515409rsync: rsync: Information disclosure and denial of service via crafted files-from entry

EPSS

Процентиль: 41%
0.00509
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
18 дней назад

rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.

CVSS3: 8.2
nvd
18 дней назад

rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.

CVSS3: 8.2
msrc
8 дней назад

rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry

CVSS3: 8.2
debian
18 дней назад

rsync 3.2.5 before 3.5.0contains a heap out-of-bounds write vulnerabil ...

suse-cvrf
11 дней назад

Security update for rsync

EPSS

Процентиль: 41%
0.00509
Низкий

8.2 High

CVSS3

Уязвимость CVE-2026-70461