CVE-2026-70456

NameCVE-2026-70456
Descriptionrsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rsync (PTS)bookworm3.2.7-1+deb12u6vulnerable
bookworm (security)3.2.7-1+deb12u5vulnerable
trixie3.4.1+ds1-5+deb13u4vulnerable
trixie (security)3.4.1+ds1-5+deb13u3vulnerable
forky, sid3.5.0+ds1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rsyncsource(unstable)3.5.0+ds1-1

Notes

https://download.samba.org/pub/rsync/NEWS#3.5.0

Search for package or bug name: Reporting problems