In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade rsync-daemonUpgrade rsyncUpgrade rsync-rrsync | May 17, 2026 | May 14, 2026 |
| Alpine Linux | — | Upgrade rsync | Apr 23, 2026 | Apr 16, 2026 |
| Debian | — | Upgrade rsync | Jun 22, 2026 | Jun 22, 2026 |
| Gentoo Linux | — | Upgrade net-misc/rsync. | Aug 16, 2026 | Aug 13, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jul 2, 2026 | Jul 1, 2026 |
| Oracle_linux | — | Upgrade rsyncUpgrade rsync-daemon | May 21, 2026 | Apr 16, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Apr 16, 2026 |
| Redhat_linux | — | Upgrade rsyncUpgrade rsync-rrsyncUpgrade rsync-debuginfoUpgrade rsync-daemonUpgrade rsync-debugsource | May 18, 2026 | Apr 16, 2026 |
| Rocky_linux | — | Upgrade rsync-debugsourceUpgrade rsyncUpgrade rsync-debuginfo | May 18, 2026 | May 15, 2026 |
| Ubuntu | — | Upgrade rsyncUpgrade rsync (Ubuntu Pro) | May 25, 2026 | May 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 5, 2026 | Apr 16, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub