https://seclists.org/oss-sec/2026/q2/146: UAF in rsync 3.4.1 and below
Published Apr 16, 2026
·Updated
Affected Software
1 affected component
rsync rsync<=3.4.1
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is critical due to the potential for unintentional memory access that can lead to remote code execution.
2
How do I fix CVE-2026-XXXX?
To mitigate CVE-2026-XXXX, upgrade to rsync version 3.4.2 or later, which contains the necessary patches.
3
What is the impact of CVE-2026-XXXX?
CVE-2026-XXXX can allow an attacker to exploit the use-after-free condition, potentially leading to arbitrary code execution.
4
Is CVE-2026-XXXX present in earlier versions of rsync?
Yes, CVE-2026-XXXX affects rsync versions 3.4.1 and below, introduced in an earlier commit from version 3.0.1pre1.
5
Who is affected by CVE-2026-XXXX?
Any user or organization using rsync versions 3.4.1 or older is vulnerable to CVE-2026-XXXX and should take immediate action to upgrade.