A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The
malicious
rsync client requires at least read access to the remote rsync module in order to trigger the issue.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade rsync-daemonUpgrade rsync-rrsyncUpgrade rsync | Apr 3, 2026 | Apr 1, 2026 |
| Alpine Linux | — | Upgrade rsync | Nov 20, 2025 | Nov 18, 2025 |
| Amazon Linux Ami 2 | — | Upgrade rsyncUpgrade rsync-debuginfo | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade rsyncUpgrade rsync-debuginfoUpgrade rsync-debugsourceUpgrade rsync-daemon | Dec 9, 2025 | Nov 18, 2025 |
| Debian | — | Upgrade rsync | Jan 12, 2026 | Jan 12, 2026 |
| Huawei Euleros 2_0_sp10 | — | Upgrade rsync | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp11 | — | Upgrade rsync | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade rsync | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade rsync | Mar 10, 2026 | Mar 10, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jul 1, 2026 | Jul 1, 2026 |
| Oracle_linux | — | Upgrade rsync-rrsyncUpgrade rsyncUpgrade rsync-daemon | Apr 22, 2026 | Nov 18, 2025 |
| Redhat_linux | — | No solution existsUpgrade rsync-rrsyncUpgrade rsyncUpgrade rsync-debugsourceUpgrade rsync-debuginfoUpgrade rsync-daemon | Apr 3, 2026 | Nov 18, 2025 |
| Rocky_linux | — | Upgrade rsyncUpgrade rsync-debugsourceUpgrade rsync-debuginfo | Apr 8, 2026 | Apr 7, 2026 |
| Ubuntu | — | Upgrade rsync (Ubuntu Pro)Upgrade rsync | May 25, 2026 | May 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 22, 2026 | Nov 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub