CVE-2026-43617
published 2026-05-20CVE-2026-43617: Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when…
PriorityP430medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.28%
20.2th percentile
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| rsyncproject | rsync | < 3.4.3 | 3.4.3 |
| samba | rsync | <= 3.4.2 | — |
| samba | rsync | — | — |
| ubuntu | rsync | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rsync regression
vendor_ubuntu·2026-06-16·CVSS 4.3
CVE-2025-10158 [MEDIUM] rsync regression
Title: rsync regression
Summary: USN-8349-1 introduced regressions in rsync.
USN-8349-1 fixed vulnerabilities in rsync. Unfortunately that update introduced multiple
regressions in rsync functionality. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to o
Ubuntu
rsync regression
vendor_ubuntu·2026-06-08·CVSS 4.3
CVE-2025-10158 [MEDIUM] rsync regression
Title: rsync regression
Summary: USN-8349-1 introduced regressions in rsync.
USN-8349-1 fixed vulnerabilities in rsync. The update introduced multiple
regressions in rsync functionality. This update fixes the problem.
Original advisory details:
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or esc
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2026-06-01·CVSS 4.3
CVE-2026-43618 [MEDIUM] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)
It was discovered that rsync did not properly validate a length value
while sorting extended attributes. An attacker could possi
Red Hat
rsync: rsync: Hostname-based ACL bypass in daemon chroot configuration
vendor_redhat·2026-05-20·CVSS 6.3
CVE-2026-43617 [MEDIUM] CWE-289 rsync: rsync: Hostname-based ACL bypass in daemon chroot configuration
rsync: rsync: Hostname-based ACL bypass in daemon chroot configuration
A flaw was found in rsync. When an rsync daemon is configured with "daemon chroot = /X" and uses hostname-based access control lists (ACLs), and the chrooted directory /X lacks necessary DNS resolution files, a remote attacker can bypass hostname-based deny rules. This occurs because the daemon performs reverse-DNS lookups after chrooting, causing the lookup to fail and the connecting hostname to be identified as "UNKNOWN". An attacker can exploit this by controlling their pointer (PTR) record, enabling unauthorized connections from hostnames that should have been denied.
Statement: This Moderate flaw in rsync allows an attacker to bypass hostname-based access controls on an rsync daemon configured with `daemon chroot
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2026-05-20·CVSS 4.3
CVE-2026-43620 [MEDIUM] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 25.10. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)
It was discovered that rsync did not properly val
VulDB
RsyncProject rsync up to 3.4.2 Access Control List authentication by alternate name (GHSA-rjfm-3w2m-jf4f / Nessus ID 315780)
vuldb·2026-06-02·CVSS 6.3
CVE-2026-43617 [MEDIUM] RsyncProject rsync up to 3.4.2 Access Control List authentication by alternate name (GHSA-rjfm-3w2m-jf4f / Nessus ID 315780)
A vulnerability was found in RsyncProject rsync up to 3.4.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Access Control List Handler. Executing a manipulation can lead to authentication bypass by alternate name.
The identification of this vulnerability is CVE-2026-43617. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-4j4q-473w-9q2r: Rsync version 3
ghsa_unreviewed·2026-05-20
CVE-2026-43617 [MEDIUM] CWE-289 GHSA-4j4q-473w-9q2r: Rsync version 3
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.
No detection rules found.
No public exploits indexed.
2026-05-20
Published