Logo
vulnerabilityCVE-2026-43618
Name
CVE-2026-43618
Source
NVD ( link)Debian ( link)
Description
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
rsync
Exploitable

Vulnerability Ratings#


6.1
CVSSv4
8.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.4.4
Not Affected
buildroot
master
3.4.4
Not Affected
openwrt
master
3.4.4-r1
Not Affected
yocto
kirkstone
3.2.7
Exploitable
yocto
master
3.4.4
Not Affected