Integer overflow in Rsync - CVE-2026-43618
Published: June 1, 2026
Rsync
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an integer overflow in the compressed-token decoder when processing compressed token data from an authenticated daemon connection. A remote user can send crafted compressed-token data to disclose sensitive information.
The disclosed memory may include environment variables, passwords, heap data, and library pointers.