Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-70456

Опубликовано: 13 авг. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 8.2

Описание

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

РелизСтатусПримечание
devel

needs-triage

esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

needs-triage

Показывать по

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
18 дней назад

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

CVSS3: 8.2
nvd
18 дней назад

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

CVSS3: 8.2
msrc
8 дней назад

rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()

CVSS3: 8.2
debian
18 дней назад

rsync 3.0.1 before 3.5.0contains an out-of-bounds write vulnerability ...

suse-cvrf
11 дней назад

Security update for rsync

8.2 High

CVSS3