PT-2026-42054 · Rsync+2 · Rsync+2

·

CVE-2026-43620

·

Published

2026-05-20

·

Updated

2026-06-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.4.3
Description A receiver-side out-of-bounds array read exists in the recv files() function within receiver.c. A malicious rsync server can trigger a deterministic SIGSEGV crash of the rsync client process by setting CF INC RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM TRANSFER. This sequence causes the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address.
Recommendations Update to version 3.4.3 or later.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43620
ECHO-1F95-ED49-F41F
GHSA-28PW-R563-RXVM
JLSEC-2026-631
OESA-2026-2549
OESA-2026-2550
OESA-2026-2551
OESA-2026-2552
OPENSUSE-SU-2026:10857-1
OPENSUSE-SU-2026:20877-1
SUSE-SU-2026:2038-1
SUSE-SU-2026:2048-1
SUSE-SU-2026:2083-1
SUSE-SU-2026:21726-1
SUSE-SU-2026:21739-1
SUSE-SU-2026:21980-1
SUSE-SU-2026:22015-1
USN-8283-1
USN-8349-1
USN-8349-2
USN-8349-3

Affected Products

Linuxmint
Ubuntu
Rsync