Inefficient Algorithmic Complexity in Rsync - CVE-2026-70453
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in hash_search() when processing a crafted checksum set containing a long chain of equal weak checksums. A remote attacker can send a specially crafted checksum set to cause a denial of service.
Sustained CPU consumption can persist as shared host resource exhaustion rather than being limited to the attacker\'s own transfer.