Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and metadata values before use. An attacker who can place or modify a SquashFS image in storage exposed through an rclone :archive: remote can craft a malicious image that triggers an integer division-by-zero panic (zero block size), an out-of-bounds slice panic (out-of-range inode metadata offset), or a non-progress CPU loop (truncated metadata stream). Variants 1 and 2 terminate the rclone process and, via 'rclone serve sftp', can crash the entire SFTP server; variant 3 causes sustained CPU consumption. Parsing is lazy, so a victim or remote client must address or descend into the malicious archive object to trigger it. | |
| Title | rclone Archive Backend SquashFS Parser Denial of Service | |
| First Time appeared |
Rclone
Rclone rclone |
|
| Weaknesses | CWE-129 | |
| CPEs | cpe:2.3:a:rclone:rclone:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Rclone
Rclone rclone |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T16:08:49.589Z
Reserved: 2026-08-25T14:29:43.528Z
Link: CVE-2026-79775
Updated: 2026-08-25T16:08:21.642Z
Status : Received
Published: 2026-08-25T16:17:29.233
Modified: 2026-08-25T17:18:18.013
Link: CVE-2026-79775
No data.
OpenCVE Enrichment
Updated: 2026-08-25T17:45:04Z