PT-2026-42051 · Rsync+2 · Rsync+2
Joshua Rogers
·
Published
2026-05-20
·
Updated
2026-06-01
·
CVE-2026-43617
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.4.3
Description
An authorization bypass exists in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record (a DNS record that maps an IP address to a hostname) for their source IP address. This allows connections from hostnames that administrators intended to deny in scenarios where reverse DNS resolution fails and defaults to UNKNOWN.
Recommendations
Update to version 3.4.3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Rsync