CVE-2026-41035
published 2026-04-16CVE-2026-41035: In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.39%
31.5th percentile
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samba | rsync | — | — |
| samba | rsync | 3.0.1 – 3.4.1 | — |
| ubuntu | rsync | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat7.4HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rsync regression
vendor_ubuntu·2026-06-16·CVSS 4.3
CVE-2025-10158 [MEDIUM] rsync regression
Title: rsync regression
Summary: USN-8349-1 introduced regressions in rsync.
USN-8349-1 fixed vulnerabilities in rsync. Unfortunately that update introduced multiple
regressions in rsync functionality. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to o
Ubuntu
rsync regression
vendor_ubuntu·2026-06-08·CVSS 4.3
CVE-2025-10158 [MEDIUM] rsync regression
Title: rsync regression
Summary: USN-8349-1 introduced regressions in rsync.
USN-8349-1 fixed vulnerabilities in rsync. The update introduced multiple
regressions in rsync functionality. This update fixes the problem.
Original advisory details:
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or esc
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2026-06-01·CVSS 4.3
CVE-2026-43618 [MEDIUM] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)
It was discovered that rsync did not properly validate a length value
while sorting extended attributes. An attacker could possi
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2026-05-20·CVSS 4.3
CVE-2026-43620 [MEDIUM] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 25.10. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)
It was discovered that rsync did not properly val
Red Hat
rsync: Rsync: Use-after-free vulnerability in extended attribute handling
vendor_redhat·2026-04-16·CVSS 7.4
CVE-2026-41035 [HIGH] CWE-805 rsync: Rsync: Use-after-free vulnerability in extended attribute handling
rsync: Rsync: Use-after-free vulnerability in extended attribute handling
A flaw was found in rsync. When rsync is configured to handle extended attributes (using the -X or --xattrs option), a remote attacker can exploit a use-after-free vulnerability. This occurs because the receive_xattr function incorrectly processes an untrusted length value during a sorting operation, leading to memory corruption. Successful exploitation can result in a denial of service, causing the rsync process to crash, and may potentially allow for arbitrary code execution.
Package: rsync (Red Hat Enterprise Linux 10) - Affected
Package: rsync (Red Hat Enterprise Linux 6) - Affected
Package: rsync (Red Hat Enterprise Linux 7) - Affected
Package: rsync (Red Hat Enterprise Linux 8) - Affected
Package: rsync (
VulDB
Samba rsync up to 3.4.1 Qsort Call receive_xattr length length parameter
vuldb·2026-04-16·CVSS 7.4
CVE-2026-41035 [HIGH] Samba rsync up to 3.4.1 Qsort Call receive_xattr length length parameter
A vulnerability classified as critical was found in Samba rsync up to 3.4.1. Affected by this vulnerability is the function receive_xattr of the component Qsort Call Handler. Such manipulation of the argument length leads to improper handling of length parameter inconsistency.
This vulnerability is documented as CVE-2026-41035. The attack can be executed remotely. There is not any exploit available.
GHSA
GHSA-m34r-4v3r-pp9v: In rsync 3
ghsa_unreviewed·2026-04-16
CVE-2026-41035 [HIGH] CWE-130 GHSA-m34r-4v3r-pp9v: In rsync 3
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41035 rsync: Rsync: Use-after-free vulnerability in extended attribute handling [fedora-all]
bugzilla·2026-04-17·CVSS 7.4
CVE-2026-41035 [HIGH] CVE-2026-41035 rsync: Rsync: Use-after-free vulnerability in extended attribute handling [fedora-all]
CVE-2026-41035 rsync: Rsync: Use-after-free vulnerability in extended attribute handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41035 rsync-bpc: Rsync: Use-after-free vulnerability in extended attribute handling [epel-all]
bugzilla·2026-04-17·CVSS 7.4
CVE-2026-41035 [HIGH] CVE-2026-41035 rsync-bpc: Rsync: Use-after-free vulnerability in extended attribute handling [epel-all]
CVE-2026-41035 rsync-bpc: Rsync: Use-after-free vulnerability in extended attribute handling [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41035 rsync-bpc: Rsync: Use-after-free vulnerability in extended attribute handling [fedora-all]
bugzilla·2026-04-17·CVSS 7.4
CVE-2026-41035 [HIGH] CVE-2026-41035 rsync-bpc: Rsync: Use-after-free vulnerability in extended attribute handling [fedora-all]
CVE-2026-41035 rsync-bpc: Rsync: Use-after-free vulnerability in extended attribute handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41035 rsync: Rsync: Use-after-free vulnerability in extended attribute handling
bugzilla·2026-04-16·CVSS 7.4
CVE-2026-41035 [HIGH] CVE-2026-41035 rsync: Rsync: Use-after-free vulnerability in extended attribute handling
CVE-2026-41035 rsync: Rsync: Use-after-free vulnerability in extended attribute handling
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
https://github.com/RsyncProject/rsync/issues/871https://github.com/RsyncProject/rsync/releaseshttps://www.openwall.com/lists/oss-security/2026/04/16/2http://www.openwall.com/lists/oss-security/2026/04/16/9http://www.openwall.com/lists/oss-security/2026/04/22/3https://access.redhat.com/errata/RHSA-2026:17481https://access.redhat.com/errata/RHSA-2026:19152https://access.redhat.com/errata/RHSA-2026:19368https://access.redhat.com/errata/RHSA-2026:20601https://access.redhat.com/errata/RHSA-2026:20602https://access.redhat.com/errata/RHSA-2026:20603https://access.redhat.com/errata/RHSA-2026:20604https://access.redhat.com/errata/RHSA-2026:20696https://access.redhat.com/errata/RHSA-2026:23233https://access.redhat.com/errata/RHSA-2026:23245https://access.redhat.com/errata/RHSA-2026:25044https://access.redhat.com/errata/RHSA-2026:25149https://access.redhat.com/errata/RHSA-2026:25170https://access.redhat.com/errata/RHSA-2026:25172https://access.redhat.com/errata/RHSA-2026:25173https://access.redhat.com/errata/RHSA-2026:25181https://access.redhat.com/errata/RHSA-2026:25190https://access.redhat.com/errata/RHSA-2026:26542https://access.redhat.com/errata/RHSA-2026:28887https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:34098https://access.redhat.com/security/cve/CVE-2026-41035https://bugzilla.redhat.com/show_bug.cgi?id=2458898https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41035.json
2026-04-16
Published