CVE-2026-43618
published 2026-05-20CVE-2026-43618: Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for…
PriorityP350high8.1CVSS 3.1
AVNACLPRLUINSUCHINAH
EPSS
0.78%
51.9th percentile
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| rsyncproject | rsync | < 3.4.3 | 3.4.3 |
| samba | rsync | <= 3.4.2 | — |
| samba | rsync | — | — |
| ubuntu | rsync | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv4.06.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.1MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rsync regression
vendor_ubuntu·2026-06-16·CVSS 4.3
CVE-2025-10158 [MEDIUM] rsync regression
Title: rsync regression
Summary: USN-8349-1 introduced regressions in rsync.
USN-8349-1 fixed vulnerabilities in rsync. Unfortunately that update introduced multiple
regressions in rsync functionality. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to o
Ubuntu
rsync regression
vendor_ubuntu·2026-06-08·CVSS 4.3
CVE-2025-10158 [MEDIUM] rsync regression
Title: rsync regression
Summary: USN-8349-1 introduced regressions in rsync.
USN-8349-1 fixed vulnerabilities in rsync. The update introduced multiple
regressions in rsync functionality. This update fixes the problem.
Original advisory details:
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or esc
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2026-06-01·CVSS 4.3
CVE-2026-43618 [MEDIUM] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)
It was discovered that rsync did not properly validate a length value
while sorting extended attributes. An attacker could possi
Red Hat
rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding
vendor_redhat·2026-05-20·CVSS 6.1
CVE-2026-43618 [MEDIUM] CWE-190 rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding
rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding
A flaw was found in rsync. An authenticated daemon peer can exploit an integer overflow vulnerability in the compressed-token decoder. By carefully manipulating the compressed-token, a malicious sender can trigger an overflow, leading to remote memory disclosure. This allows an attacker to leak sensitive process memory contents, including environment variables, passwords, and memory pointers, which significantly weakens Address Space Layout Randomization (ASLR) and can facilitate further exploitation.
Statement: This flaw in rsync's compressed-token decoding allows an authenticated remote attacker to trigger an integer overflow. This can lead to memory disclosure, potentially exposing sensitive infor
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2026-05-20·CVSS 4.3
CVE-2026-43620 [MEDIUM] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 25.10. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)
It was discovered that rsync did not properly val
VulDB
RsyncProject rsync up to 3.4.2 integer overflow (GHSA-g37v-g3gj-pmwq / Nessus ID 315780)
vuldb·2026-06-02·CVSS 6.1
CVE-2026-43618 [MEDIUM] RsyncProject rsync up to 3.4.2 integer overflow (GHSA-g37v-g3gj-pmwq / Nessus ID 315780)
A vulnerability categorized as critical has been discovered in RsyncProject rsync up to 3.4.2. This affects an unknown part. The manipulation results in integer overflow.
This vulnerability is identified as CVE-2026-43618. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-88m5-cm5m-2596: Rsync version 3
ghsa_unreviewed·2026-05-20
CVE-2026-43618 [MEDIUM] CWE-125 GHSA-88m5-cm5m-2596: Rsync version 3
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.
No detection rules found.
No public exploits indexed.
https://github.com/RsyncProject/rsync/releases/tag/v3.4.3https://github.com/RsyncProject/rsync/security/advisories/GHSA-g37v-g3gj-pmwqhttps://www.vulncheck.com/advisories/rsync-integer-overflow-information-disclosurehttps://access.redhat.com/errata/RHSA-2026:26332https://access.redhat.com/errata/RHSA-2026:26408https://access.redhat.com/errata/RHSA-2026:26410https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/security/cve/CVE-2026-43618https://bugzilla.redhat.com/show_bug.cgi?id=2469054https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43618.json
2026-05-20
Published