A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The
malicious
rsync client requires at least read access to the remote rsync module in order to trigger the issue.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade rsync-rrsyncUpgrade rsync-daemonUpgrade rsync | Apr 3, 2026 | Apr 1, 2026 |
| Alpine Linux | — | Upgrade rsync | Nov 20, 2025 | Nov 18, 2025 |
| Amazon Linux Ami 2 | — | Upgrade rsync-debuginfoUpgrade rsync | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade rsyncUpgrade rsync-daemonUpgrade rsync-debuginfoUpgrade rsync-debugsource | Dec 9, 2025 | Nov 18, 2025 |
| Debian | — | Upgrade rsync | Jan 12, 2026 | Jan 12, 2026 |
| Huawei Euleros 2_0_sp10 | — | Upgrade rsync | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp11 | — | Upgrade rsync | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade rsync | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade rsync | Mar 10, 2026 | Mar 10, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jul 1, 2026 | Jul 1, 2026 |
| Oracle_linux | — | Upgrade rsyncUpgrade rsync-rrsyncUpgrade rsync-daemon | Apr 22, 2026 | Nov 18, 2025 |
| Redhat_linux | — | Upgrade rsync-daemonUpgrade rsync-debuginfoUpgrade rsync-debugsourceNo solution existsUpgrade rsyncUpgrade rsync-rrsync | Apr 3, 2026 | Nov 18, 2025 |
| Rocky_linux | — | Upgrade rsync-debugsourceUpgrade rsyncUpgrade rsync-debuginfo | Apr 8, 2026 | Apr 7, 2026 |
| Ubuntu | — | Upgrade rsync (Ubuntu Pro)Upgrade rsync | May 25, 2026 | May 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 22, 2026 | Nov 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub