Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

ubuntu логотип

CVE-2026-43620

3 месяца назад

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address, resulting in a deterministic SIGSEGV crash of the rsync client.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-43620

3 месяца назад

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address, resulting in a deterministic SIGSEGV crash of the rsync client.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-43620

3 месяца назад

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address, resulting in a deterministic SIGSEGV crash of the rsync client.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-43620

3 месяца назад

Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-43620

3 месяца назад

Rsync version3.4.2 and prior contain a receiver-side out-of-bounds arr ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jmf6-74r8-6c28

3 месяца назад

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address, resulting in a deterministic SIGSEGV crash of the rsync client.

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20877-1

2 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2083-1

2 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2048-1

2 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2038-1

3 месяца назад

Security update for rsync

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-43620

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address, resulting in a deterministic SIGSEGV crash of the rsync client.

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-43620

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address, resulting in a deterministic SIGSEGV crash of the rsync client.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-43620

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address, resulting in a deterministic SIGSEGV crash of the rsync client.

CVSS3: 6.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-43620

Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()

CVSS3: 6.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-43620

Rsync version3.4.2 and prior contain a receiver-side out-of-bounds arr ...

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-jmf6-74r8-6c28

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address, resulting in a deterministic SIGSEGV crash of the rsync client.

CVSS3: 6.5
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20877-1

Security update for rsync

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2083-1

Security update for rsync

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2048-1

Security update for rsync

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2038-1

Security update for rsync

3 месяца назад

Уязвимостей на страницу