Out-of-Bounds Array Read in Rsync File Synchronization Tool
CVE-2026-44510

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-44510?

Rsync, a file-copying tool utilizing a delta-transfer algorithm, is susceptible to an out-of-bounds array read in its recv_files() function. This vulnerability allows a malicious rsync server to deterministically crash any client that connects to it. The exploitation can occur without any special options on the client's end and affects both rsync:// URLs and remote-shell pulls. By manipulating the file list sent during a transfer, the attacker can cause the client to read beyond allocated memory, leading to a crash. The vulnerability presents a crash-only impact, verified in glibc x86-64 Linux, but remains non-leveragable for exploitation. This issue has been addressed in version 3.4.3.

Affected Version(s)

rsync < 3.4.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.