PT-2026-61713 · Rsync · Rsync

CVE-2026-44507

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.4.3
Description When using a daemon configured with a chroot, the reverse DNS lookup of the connecting client is performed after the chroot has been entered. If the chroot environment lacks the necessary glibc files for resolution, such as /etc/resolv.conf, /etc/nsswitch.conf, /etc/hosts, or NSS service modules, the lookup fails and the hostname is set to "UNKNOWN". This allows an attacker controlling the PTR record of their source IP to bypass hostname-based deny rules, as the rules cannot match the "UNKNOWN" status. IP-based Access Control Lists (ACLs) remain unaffected.
Recommendations Update to version 3.4.3.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44507

Affected Products

Rsync