https://seclists.org/oss-sec/2026/q2/151: UAF in rsync 3.4.1 and below
Published Apr 16, 2026
·Updated
Affected Software
1 affected component
rsync rsync<=3.4.1
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is considered high due to the potential for uninitialized memory access leading to exploitation.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, upgrade to rsync version 3.4.2 or later where the vulnerability has been addressed.
3
What systems are affected by CVE-2026-XXXX?
CVE-2026-XXXX affects all versions of rsync from 3.4.1 and below.
4
What type of vulnerability is CVE-2026-XXXX?
CVE-2026-XXXX is classified as a Use After Free (UAF) vulnerability.
5
Can CVE-2026-XXXX lead to remote code execution?
Yes, CVE-2026-XXXX can potentially allow an attacker to execute arbitrary code remotely.