Known vulnerabilities in rsync (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:rsync_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 12
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rsync (Red Hat package) rsync (Red Hat package) is affected by 12 known vulnerabilities: 1 high, 6 medium, 5 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU133359 - Use After Free
CVE-2026-41035
CWE-416 Medium
No
No
3.0.6-12.el6_10.3, 3.1.2-12.el7_9.3, 3.1.3-12.el8_4.7, 3.1.3-14.el8_6.10, 3.1.3-20.el8_8.5, 3.1.3-25.el8_10, 3.4.1-2.el10_0.2 04.06.2026 SB2026060475
SB2026060476
SB2026060477
and 25 more
#VU133144 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-29518
CWE-367 Low
No
No
3.2.5-7.el9_8.2, 3.4.4-1.el10_2 01.06.2026 SB2026060174
SB2026060175
SB2026060184
and 18 more
#VU133146 - Integer overflow
CVE-2026-43618
CWE-190 Low
No
No
3.2.5-7.el9_8.2, 3.4.4-1.el10_2 01.06.2026 SB2026060174
SB2026060175
SB2026060184
and 24 more
#VU120348 - Out-of-bounds read
CVE-2025-10158
CWE-125 Medium
No
No
3.1.3-24.el8_10, 3.2.5-3.el9_7.2, 3.4.1-2.el10_0.2 26.12.2025 SB2025122689
SB2025122697
SB2025122698
and 27 more
#VU102739 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-12747
CWE-362 Low
No
No
3.1.3-21.el8_10 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 56 more
#VU102736 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12088
CWE-22 Medium
No
No
3.1.3-21.el8_10 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 65 more
#VU102734 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12087
CWE-22 Medium
No
No
3.0.6-12.el6_10.2, 3.1.2-12.el7_9.2, 3.1.3-7.el8_2.6, 3.1.3-12.el8_4.6, 3.1.3-14.el8_6.9, 3.1.3-20.el8_8.4, 3.1.3-21.el8_10, 3.2.3-19.el9_4.2 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 74 more
#VU102730 - Use of Uninitialized Variable
CVE-2024-12085
CWE-457 Medium
No
No
3.0.6-12.el6_10.1, 3.1.2-12.el7_9.1, 3.1.3-7.el8_2.3, 3.1.3-12.el8_4.3, 3.1.3-14.el8_6.6, 3.1.3-20.el8_8.1, 3.1.3-20.el8_10, 3.2.3-9.el9_0.3, 3.2.3-19.el9_2.1, 3.2.3-19.el9_4.1, 3.2.3-20.el9_5.1 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 92 more
#VU66189 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-29154
CWE-22 Low
No
No
3.1.2-11.el7_9, 3.1.3-6.el8_1.2, 3.1.3-7.el8_2.2, 3.1.3-12.el8_4.2, 3.1.3-14.el8_6.3, 3.2.3-9.el9_0.2 08.08.2022 SB2022080837
SB2022081645
SB2022081649
and 70 more
#VU66153 - Heap-based Buffer Overflow
CVE-2022-37434
CWE-122 High
Available
No
3.1.3-14.el8_6.5, 3.1.3-19.el8, 3.2.3-18.el9 07.08.2022 SB2022080705
SB2022081833
SB2022081851
and 154 more
#VU61671 - Memory corruption
CVE-2018-25032
CWE-119 Medium
No
No
3.1.3-6.el8_1.1, 3.1.3-7.el8_2.1, 3.1.3-12.el8_4.1, 3.1.3-14.el8_6.2, 3.2.3-9.el9_0.1 28.03.2022 SB2022032844
SB2022032845
SB2022033018
and 192 more
#VU6663 - Out-of-bounds read
CVE-2016-9840
CWE-125 Low
No
No
3.1.3-7.el8_2.5, 3.1.3-12.el8_4.5, 3.1.3-14.el8_6.8, 3.1.3-20.el8_8.3, 3.1.3-23.el8_10 24.05.2017 SB2017052312
SB2017052405
SB2017052406
and 47 more