Rsync File-Copying Tool Vulnerability in Chroot Configurations by Rsync
CVE-2026-44507

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-44507?

Rsync, a popular tool for file synchronization, has a vulnerability in its daemon configuration when utilized within a chroot environment. If the chroot setup does not include necessary resolution files, such as /etc/resolv.conf or /etc/hosts, the system fails to resolve the hostname of connecting clients properly. This can lead to situations where hostname-based access restrictions are ineffective, allowing unauthorized connections from potentially malicious users who control their PTR records. This issue, present in versions released before 3.4.3, has been addressed and resolved in the latest update.

Affected Version(s)

rsync < 3.4.3

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.