https://seclists.org/oss-sec/2026/q2/198: UAF in rsync 3.4.1 and below
Published Apr 21, 2026
·Updated
Affected Software
1 affected component
rsync rsync<=3.4.1
Frequently Asked Questions
1
What is the severity of UAF in rsync 3.4.1 and below?
The UAF vulnerability in rsync 3.4.1 and below is considered critical due to the potential for arbitrary code execution.
2
How do I fix UAF in rsync 3.4.1 and below?
To fix the UAF vulnerability in rsync 3.4.1 and below, upgrade to rsync version 3.4.2 or later.
3
What causes the UAF vulnerability in rsync 3.4.1 and below?
The UAF vulnerability in rsync 3.4.1 and below is caused by improper handling of memory, leading to the possibility of accessing freed memory.
4
Is the UAF vulnerability in rsync 3.4.1 and below remotely exploitable?
Yes, the UAF vulnerability in rsync 3.4.1 and below can be remotely exploitable under certain conditions.
5
When was the UAF vulnerability in rsync 3.4.1 and below discovered?
The UAF vulnerability in rsync 3.4.1 and below was discovered on April 15, 2026.