REDHAT-BUG-2458898: Use After Free
In rsync 3.0.1 through 3.4.1, receivexattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2458898?
The severity of REDHAT-BUG-2458898 is high, rated at 7.
How do I fix REDHAT-BUG-2458898?
To fix REDHAT-BUG-2458898, update rsync to a non-vulnerable version after ensuring that you are not using the -X option.
What platforms are affected by REDHAT-BUG-2458898?
REDHAT-BUG-2458898 affects many common Linux configurations as well as some non-Linux platforms.
What is the primary risk associated with REDHAT-BUG-2458898?
The primary risk associated with REDHAT-BUG-2458898 is a receiver use-after-free vulnerability during the qsort call.
What versions of rsync are affected by REDHAT-BUG-2458898?
Rsync versions from 3.0.1 through 3.4.1 are affected by REDHAT-BUG-2458898.