PT-2026-61714 · Rsync · Rsync

CVE-2026-44508

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.4.3
Description rsync is a file-copying tool utilizing a delta-transfer algorithm to synchronize files. The receiver's compressed-token decoder fails to check for overflow when accumulating a 32-bit signed counter. A malicious sender can trigger this overflow to extract sensitive data from the process memory, including passwords, environment variables, and memory pointers from the heap, stack, and libraries. This leakage can reduce the effectiveness of Address Space Layout Randomization (ASLR), which is a security technique that randomly arranges the address space positions of key data areas of a process to make exploitation more difficult.
Recommendations Update to version 3.4.3.

Fix

Integer Overflow

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44508

Affected Products

Rsync