Signed Integer Overflow Vulnerability in Rsync by RsyncProject
CVE-2026-70462

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-70462?

Rsync versions prior to 3.5.0 contain a vulnerability that allows attackers to exploit the I/O timeout mechanism through specially crafted MSG_IO_TIMEOUT messages. By injecting non-positive values, an attacker can manipulate the timeout variable to bypass checks, leading to the potential exhaustion of server resources as idle connections can persist indefinitely. This vulnerability poses a risk to systems running affected versions of rsync, enabling attackers to disrupt service availability.

Affected Version(s)

rsync 3.1.0 <= 3.4.4

rsync 3.5.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

z3r0s6
buger
.