CVE-2026-44510: Rsync: Receiver-side out-of-bounds read enables remote DoS from malicious server
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.4.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44510?
CVE-2026-44510 has a medium severity score of 6.5.
What does CVE-2026-44510 describe?
CVE-2026-44510 describes a receiver-side out-of-bounds read vulnerability in Rsync that enables remote DoS from a malicious server.
How should I address CVE-2026-44510?
Since CVE-2026-44510 is rejected as a duplicate, you should reference CVE-2026-43620 for any mitigation or fixes.
Is CVE-2026-44510 still applicable for exploitation?
CVE-2026-44510 is not applicable as it has been rejected and should not be used.
When was CVE-2026-44510 published and modified?
CVE-2026-44510 was published on July 20, 2026, and modified on July 21, 2026.