Integer overflow in Rsync - CVE-2026-70462
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in MSG_IO_TIMEOUT handling when processing a peer-supplied MSG_IO_TIMEOUT message. A remote attacker can send a specially crafted timeout value to cause a denial of service.
User interaction is required because MSG_IO_TIMEOUT is accepted only by the connecting client.