Описание
Security update for rsync
This update for rsync fixes the following issues
- CVE-2025-10158: Out of bounds array access via negative index (bsc#1254441).
- CVE-2026-41035: count of entries mismatch can lead to a use-after-free (bsc#1262223).
Список пакетов
openSUSE Leap 16.0
rsync-3.4.1-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1254441
- SUSE Bug 1262223
- SUSE CVE CVE-2025-10158 page
- SUSE CVE CVE-2026-41035 page
Описание
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.
Затронутые продукты
openSUSE Leap 16.0:rsync-3.4.1-160000.3.1
Ссылки
- CVE-2025-10158
- SUSE Bug 1254441
Описание
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
Затронутые продукты
openSUSE Leap 16.0:rsync-3.4.1-160000.3.1
Ссылки
- CVE-2026-41035
- SUSE Bug 1262223