PT-2024-10103 · Rsync+1 · Rsync+1

Published

2024-01-01

·

Updated

2025-10-08

·

CVE-2024-48943

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions rsync (affected versions not specified)
Description The issue is related to an uncontrolled resource consumption in the rsync repository validator FORT. It can be exploited by a remote attacker to elevate their privileges. A malicious RPKI rsync repository can prevent FORT from finishing its validation run by slowly providing its content.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2025-00321
CVE-2024-48943
DLA-4066-1
USN-7813-1

Affected Products

Debian
Rsync