PT-2026-42051 · Rsync+2 · Rsync+2

Joshua Rogers

·

Published

2026-05-20

·

Updated

2026-06-01

·

CVE-2026-43617

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.4.3
Description An authorization bypass exists in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record (a DNS record that maps an IP address to a hostname) for their source IP address. This allows connections from hostnames that administrators intended to deny in scenarios where reverse DNS resolution fails and defaults to UNKNOWN.
Recommendations Update to version 3.4.3 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-43617
ECHO-8072-9059-153B
OPENSUSE-SU-2026:10857-1
USN-8283-1
USN-8349-1

Affected Products

Linuxmint
Ubuntu
Rsync