Logo
vulnerabilityCVE-2026-43617
Name
CVE-2026-43617
Source
NVD ( link)Debian ( link)
Description
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
rsync
Exploitable

Vulnerability Ratings#


6.3
CVSSv4
4.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.4.4
Not Affected
buildroot
master
3.4.4
Not Affected
openwrt
master
3.4.4-r1
Not Affected
yocto
master
3.4.4
Not Affected
yocto
scarthgap
3.2.7
Exploitable