Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-79775

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and metadata values before use. An attacker who can place or modify a SquashFS image in storage exposed through an rclone :archive: remote can craft a malicious image that triggers an integer division-by-zero panic (zero block size), an out-of-bounds slice panic (out-of-range inode metadata offset), or a non-progress CPU loop (truncated metadata stream). Variants 1 and 2 terminate the rclone process and, via 'rclone serve sftp', can crash the entire SFTP server; variant 3 causes sustained CPU consumption. Parsing is lazy, so a victim or remote client must address or descend into the malicious archive object to trigger it.

A flaw was found in rclone. The archive backend's SquashFS parser fails to validate attacker-controlled superblock and metadata values before use. An attacker who can place or modify a malicious SquashFS image in storage exposed through an rclone :archive: remote can trigger multiple denial-of-service vulnerabilities. This can lead to an integer division-by-zero panic, an out-of-bounds slice panic, or a non-progress CPU loop, which can terminate the rclone process, potentially crash an SFTP server, or cause sustained CPU consumption.

Отчет

A flaw was found in the go-diskfs library used by rclone. The SquashFS image parser is vulnerable to denial of service when processing a maliciously crafted SquashFS image. A divide-by-zero error occurs during parsing, causing the application to panic and crash. An attacker who can supply a crafted SquashFS image to an application using go-diskfs for parsing can trigger the crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Out of support scope
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Exploit Intelligenceexploit-intelligence/agent-client-rhel9Out of support scope
Exploit Intelligenceexploit-intelligence-tech-preview/agent-client-rhel9Out of support scope
Multicluster Engine for Kubernetesmulticluster-engine/assisted-image-service-rhel8Out of support scope
Multicluster Engine for Kubernetesmulticluster-engine/assisted-image-service-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-8-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/image-based-install-rhel9Out of support scope
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=2523581github.com/diskfs/go-diskfs: rclone: Denial of Service via malicious SquashFS image parsing

EPSS

Процентиль: 23%
0.00307
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
23 дня назад

rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and metadata values before use. An attacker who can place or modify a SquashFS image in storage exposed through an rclone :archive: remote can craft a malicious image that triggers an integer division-by-zero panic (zero block size), an out-of-bounds slice panic (out-of-range inode metadata offset), or a non-progress CPU loop (truncated metadata stream). Variants 1 and 2 terminate the rclone process and, via 'rclone serve sftp', can crash the entire SFTP server; variant 3 causes sustained CPU consumption. Parsing is lazy, so a victim or remote client must address or descend into the malicious archive object to trigger it.

CVSS3: 6.5
nvd
23 дня назад

rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and metadata values before use. An attacker who can place or modify a SquashFS image in storage exposed through an rclone :archive: remote can craft a malicious image that triggers an integer division-by-zero panic (zero block size), an out-of-bounds slice panic (out-of-range inode metadata offset), or a non-progress CPU loop (truncated metadata stream). Variants 1 and 2 terminate the rclone process and, via 'rclone serve sftp', can crash the entire SFTP server; variant 3 causes sustained CPU consumption. Parsing is lazy, so a victim or remote client must address or descend into the malicious archive object to trigger it.

CVSS3: 6.5
debian
23 дня назад

rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain m ...

CVSS3: 6.5
github
23 дня назад

rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and metadata values before use. An attacker who can place or modify a SquashFS image in storage exposed through an rclone :archive: remote can craft a malicious image that triggers an integer division-by-zero panic (zero block size), an out-of-bounds slice panic (out-of-range inode metadata offset), or a non-progress CPU loop (truncated metadata stream). Variants 1 and 2 terminate the rclone process and, via 'rclone serve sftp', can crash the entire SFTP server; variant 3 causes sustained CPU consumption. Parsing is lazy, so a victim or remote client must address or descend into the malicious archive object to trigger it.

EPSS

Процентиль: 23%
0.00307
Низкий

6.5 Medium

CVSS3