CVE-2026-44507: Rsync: hostname/ACL bypass on DNS-lookup failure
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43617. Reason: This candidate is a duplicate of CVE-2026-43617. Notes: All CVE users should reference CVE-2026-43617 instead of this candidate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rsyncto a version that resolves this vulnerability.Fixed in 3.4.3 - Compensating control
Add IP-based ACLs (e.g., hosts allow = 10.0.0.0/8) because hostname-based deny rules cannot reliably match when reverse DNS lookup fails and the hostname is set to "UNKNOWN" for CVE-2026-43617.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44507?
The severity of CVE-2026-44507 is rated as medium with a score of 4.8.
How do I fix CVE-2026-44507?
To fix CVE-2026-44507, update Rsync to version 3.4.3 or later.
What is the impact of CVE-2026-44507?
CVE-2026-44507 allows for a hostname/ACL bypass when the DNS lookup fails, potentially compromising security.
Which versions are affected by CVE-2026-44507?
Versions of Rsync prior to 3.4.3 are affected by CVE-2026-44507.
What software does CVE-2026-44507 pertain to?
CVE-2026-44507 pertains to Rsync, a file-copying tool that synchronizes remote and local files.