Out-of-bounds write in Rsync - CVE-2026-70461
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in add_implied_include() when processing transfer arguments sent by a peer. A remote attacker can send a specially crafted files-from entry to cause a denial of service.
The issue is reachable on a standard network rsync daemon with a read-only module, and no crafted protocol is required.