Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer. | |
| Title | rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T17:37:54.843Z
Reserved: 2026-08-04T14:52:23.815Z
Link: CVE-2026-70461
No data.
Status : Received
Published: 2026-08-13T15:20:00.117
Modified: 2026-08-13T15:20:00.117
Link: CVE-2026-70461
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:15:05Z