Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

fstec логотип

BDU:2026-14725

около 1 месяца назад

Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2026-70455

около 1 месяца назад

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-70455

около 1 месяца назад

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-70455

около 1 месяца назад

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-70455

28 дней назад

rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-70455

около 1 месяца назад

rsync 3.4.2 before 3.5.0contains a denial of service vulnerability tha ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:67463

5 дней назад

Important: rsync security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-67463-0

5 дней назад

ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3657-1

около 1 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3634-1

около 1 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21650-1

25 дней назад

Security update for rsync

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-14725

Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.2
1%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-70455

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.

CVSS3: 7.5
1%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-70455

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.

CVSS3: 7.5
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-70455

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.

CVSS3: 7.5
1%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-70455

rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion

CVSS3: 7.5
1%
Низкий
28 дней назад
debian логотип
CVE-2026-70455

rsync 3.4.2 before 3.5.0contains a denial of service vulnerability tha ...

CVSS3: 7.5
1%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:67463

Important: rsync security, bug fix, and enhancement update

5 дней назад
oracle-oval логотип
ELSA-2026-67463-0

ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT)

5 дней назад
suse-cvrf логотип
SUSE-SU-2026:3657-1

Security update for rsync

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3634-1

Security update for rsync

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21650-1

Security update for rsync

25 дней назад

Уязвимостей на страницу