Описание
rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients.
A denial of service flaw was found in the rsync daemon. An unauthenticated remote attacker can stall the handshake process by opening multiple concurrent connections and trickling data or stalling prior to module selection. This bypasses standard timeouts and exhausts all available connection slots, preventing legitimate clients from connecting.
Отчет
An unauthenticated remote attacker can exhaust available connection slots by stalling the handshake process, preventing legitimate clients from connecting. This vulnerability primarily affects systems where the rsync daemon is explicitly enabled and exposed to untrusted networks.
Меры по смягчению последствий
Disable the rsync daemon if unused (systemctl disable --now rsyncd), or strictly restrict TCP/873 access to trusted clients using firewall rules and hosts allow directives. Do not rely on standard module timeout settings, as they do not protect against this specific pre-handshake stall. While configuring system limits (TasksMax/LimitNOFILE) can prevent full host resource exhaustion, aggressive IP-based connection filtering is the only reliable way to keep the targeted rsync module available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | rsync | Affected | ||
| Red Hat Enterprise Linux 6 | rsync | Affected | ||
| Red Hat Enterprise Linux 7 | rsync | Affected | ||
| Red Hat Enterprise Linux 8 | rsync | Affected | ||
| Red Hat Enterprise Linux 9 | rsync | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients.
rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients.
rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall
rsync daemon 2.0.0 before 3.5.0contains a denial of service vulnerabil ...
7.5 High
CVSS3