Infinite loop in rclone - #VU140644

 

Infinite loop in rclone - #VU140644

Published: August 1, 2026


Vulnerability identifier: #VU140644
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to loop with unreachable exit condition in github.com/diskfs/go-diskfs metadata parsing as used by rclone's archive backend when parsing a crafted truncated SquashFS image. A remote user can send or access a specially crafted SquashFS image to cause a denial of service.

The affected operation can continue consuming CPU after the requesting client disconnects, and repeated requests involving distinct malicious archives can amplify resource consumption.


Affected software

rclone

Remediation

Install security update from vendor's website.

rclone - update to 1.75.0

External References

Related Security Bulletins