REDHAT-BUG-2415637: Medium severity rsync rsync vulnerability
Published Nov 18, 2025
·Updated
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The
malicious
rsync client requires at least read access to the remote rsync module in order to trigger the issue.
Affected Software
1 affected component
rsync rsync
Event History
Nov 18, 2025
Data Sourced
via Red Hat·03:01 PM
DescriptionSeverityAffected Software