PT-2026-61714 · Rsync · Rsync
CVE-2026-44508
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.4.3
Description
rsync is a file-copying tool utilizing a delta-transfer algorithm to synchronize files. The receiver's compressed-token decoder fails to check for overflow when accumulating a 32-bit signed counter. A malicious sender can trigger this overflow to extract sensitive data from the process memory, including passwords, environment variables, and memory pointers from the heap, stack, and libraries. This leakage can reduce the effectiveness of Address Space Layout Randomization (ASLR), which is a security technique that randomly arranges the address space positions of key data areas of a process to make exploitation more difficult.
Recommendations
Update to version 3.4.3.
Fix
Integer Overflow
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rsync