cbcvebase.

Samba Rsync vulnerabilities

55 known vulnerabilities affecting samba/rsync.

Total CVEs
55
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH24MEDIUM19LOW3

Vulnerabilities

Page 2 of 3
CVE-2016-9842P3HIGHCVSS 8.8≥ 0, < 3.1.3-62017-05-23
CVE-2016-9842 [HIGH] CVE-2016-9842: The inflateMark function in inflate The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
osv
CVE-2026-70457P3HIGHCVSS 8.2≥ 3.2.3, < 3.5.02026-08-13
CVE-2026-70457 [HIGH] CWE-131 CVE-2026-70457: rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. When snprintf truncates the formatted size string, the return value equals the number of characters that would have been written including the truncated portion
nvd
CVE-2016-9840P3HIGHCVSS 8.8≥ 0, < 3.1.1-3ubuntu1.3≥ 0, < 3.1.2-2.1ubuntu1.12020-02-25
CVE-2016-9840 [HIGH] rsync vulnerabilities rsync vulnerabilities It was discovered that rsync incorrectly handled pointer arithmetic in zlib. An attacker could use this issue to cause rsync to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841) It was discovered that rsync incorrectly handled vectors involving left shifts of negative integers in zlib. An attacker could use this issue to cause rsync to crash, resulting in a denial of servi
osv
CVE-2026-53803P3HIGHCVSS 7.8fixed in 3.5.02026-08-13
CVE-2026-53803 [HIGH] CWE-59 CVE-2026-53803: rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwri rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to a
nvd
CVE-2020-14387P3HIGHCVSS 7.4≥ 3.2.1, < 3.2.4v3.2.0+1 more2021-05-27
CVE-2020-14387 [HIGH] CWE-297 CVE-2020-14387: A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with h A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using
nvdosv
CVE-2007-6199P3CRITICALCVSS 9.3≥ 0, < 2.6.9-62007-12-01
CVE-2007-6199 [CRITICAL] CVE-2007-6199: rsync before 3 rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.
osv
CVE-2016-9843P3CRITICALCVSS 9.8≥ 0, < 3.1.3-62017-05-23
CVE-2016-9843 [CRITICAL] CVE-2016-9843: The crc32_big function in crc32 The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
osv
CVE-2026-41035P3HIGHCVSS 7.8≥ 3.0.1, ≤ 3.4.12026-04-16
CVE-2026-41035 [HIGH] CWE-130 CVE-2026-41035: In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
nvd
CVE-2026-70455P3HIGHCVSS 7.5≥ 3.4.2, < 3.5.02026-08-13
CVE-2026-70455 [HIGH] CWE-770 CVE-2026-70455: rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to e rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstand
nvd
CVE-2008-1720P3HIGHCVSS 7.5v2.6.9v2.7.0+31 more2008-04-10
CVE-2008-1720 [HIGH] CWE-119 CVE-2008-1720: Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allo Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
nvdosv
CVE-2026-53802P3HIGHCVSS 7.1fixed in 3.5.02026-08-13
CVE-2026-53802 [HIGH] CWE-61 CVE-2026-53802: rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file p
nvd
CVE-2026-53784P3HIGHCVSS 7.1fixed in 3.5.02026-08-13
CVE-2026-53784 [HIGH] CWE-59 CVE-2026-53784: rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access file rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, caus
nvd
CVE-2026-29518P3HIGHCVSS 7.0fixed in 3.4.32026-05-20
CVE-2026-29518 [HIGH] CWE-367 CVE-2026-29518: Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite a
nvd
CVE-2004-2093P4MEDIUMCVSS 4.6PoC≥ 0, < 2.6.1-12004-02-09
CVE-2004-2093 [MEDIUM] CVE-2004-2093: Buffer overflow in the open_socket_out function in socket Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user. Therefore this issue may be REJECTED in
osv
CVE-2026-53786P3MEDIUMCVSS 6.5fixed in 3.5.02026-08-13
CVE-2026-53786 [MEDIUM] CWE-863 CVE-2026-53786: rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directives during filter evaluation to introduce rules that supersede daemon module-level restrictions, gaining
nvd
CVE-2026-43619P3MEDIUMCVSS 6.3≤ 3.4.22026-05-20
CVE-2026-43619 [MEDIUM] CWE-59 CVE-2026-43619: Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system ca Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timi
nvd
CVE-2007-4091P3MEDIUMCVSS 6.8≥ 0, < 2.6.9-52007-08-16
CVE-2007-4091 [MEDIUM] CVE-2007-4091: Multiple off-by-one errors in the sender Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.
osv
CVE-2026-53799P3MEDIUMCVSS 6.3fixed in 3.5.02026-08-13
CVE-2026-53799 [MEDIUM] CWE-59 CVE-2026-53799: rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to ca rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing win
nvd
CVE-2026-53801P3MEDIUMCVSS 5.9fixed in 3.5.02026-08-13
CVE-2026-53801 [MEDIUM] CWE-59 CVE-2026-53801: rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scannin rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender to enumerate and transfer files outside the module root's intended subtree. Attackers who can create or manipulate symlinks in a path component of the scanned tree can replace a symlink with a directory
nvd
CVE-2014-2855P3HIGHCVSS 7.8≤ 3.1.0v2.6.9+40 more2014-04-23
CVE-2014-2855 [HIGH] CWE-20 CVE-2014-2855: The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to ca The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.
nvdosv
Samba Rsync vulnerabilities | cvebase