CVE-2026-44508: Rsync: Integer overflow in compressed-token decoding
Published Jul 20, 2026
·Updated
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.
Affected Software
1 affected component
rsync rsync<3.4.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rsyncto a version that resolves this vulnerability.Fixed in 3.4.3Patch CVE-2026-43618
Event History
Jul 20, 2026
CVE Published
via MITRE·08:30 PM
Rejected
via MITRE·08:30 PM
Data Sourced
via NVD·09:16 PM
Description
Jul 21, 2026
Rejected
via MITRE·03:10 PM
Rejected
via NVD·04:17 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-44508?
The severity of CVE-2026-44508 is categorized as high, with a CVSS score of 8.1.
2
How do I fix CVE-2026-44508?
To fix CVE-2026-44508, upgrade to rsync version 3.4.3 or later.
3
What type of vulnerability is CVE-2026-44508?
CVE-2026-44508 is classified as an integer overflow vulnerability.
4
What products are affected by CVE-2026-44508?
CVE-2026-44508 affects rsync versions prior to 3.4.3.
5
Can CVE-2026-44508 lead to information leakage?
Yes, CVE-2026-44508 can potentially lead to information leakage due to the integer overflow.