PT-2026-33280 · Rsync+3 · Rsync+3

·

CVE-2026-41035

·

Published

2026-04-16

·

Updated

2026-07-10

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rsync versions 3.0.1 through 3.4.1
Description The receive xattr() function relies on an untrusted length value during a qsort() call, which can lead to a use-after-free condition on the receiver side. This occurs when the victim runs the software with the -X (or --xattrs) option. While many common configurations on Linux are affected, non-Linux platforms are more widely susceptible.
Recommendations Update rsync to a version later than 3.4.1. As a temporary workaround, avoid running rsync with the -X or --xattrs option.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:17481
ALSA-2026:19152
ALSA-2026:19368
CVE-2026-41035
ECHO-96CC-2C47-FEAB
JLSEC-2026-627
OESA-2026-2150
OPENSUSE-SU-2026:10775-1
OPENSUSE-SU-2026:20754-1
OPENSUSE-SU-2026:20877-1
RHSA-2026:17481
RHSA-2026:19152
RHSA-2026:20601
RHSA-2026:20696
RHSA-2026:25149
RHSA-2026:25170
RHSA-2026:25172
RHSA-2026:25173
RHSA-2026:25190
SUSE-SU-2026:2002-1
SUSE-SU-2026:2038-1
SUSE-SU-2026:2048-1
SUSE-SU-2026:2083-1
SUSE-SU-2026:21676-1
SUSE-SU-2026:21686-1
SUSE-SU-2026:21726-1
SUSE-SU-2026:21739-1
SUSE-SU-2026:21747-1
SUSE-SU-2026:21795-1
SUSE-SU-2026:21980-1
SUSE-SU-2026:22015-1
USN-8283-1
USN-8349-1
USN-8349-2
USN-8349-3

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Rsync