Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection. | |
| Title | rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry | |
| Weaknesses | CWE-908 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:43:32.853Z
Reserved: 2026-08-04T14:52:23.814Z
Link: CVE-2026-70459
No data.
Status : Received
Published: 2026-08-13T15:19:59.813
Modified: 2026-08-13T15:19:59.813
Link: CVE-2026-70459
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:15:05Z