rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side. | |
| Title | rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block | |
| Weaknesses | CWE-129 CWE-787 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:38:30.864Z
Reserved: 2026-06-10T20:14:32.827Z
Link: CVE-2026-53792
No data.
Status : Received
Published: 2026-08-13T15:19:43.527
Modified: 2026-08-13T15:19:43.527
Link: CVE-2026-53792
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:30:07Z