Rsync
Rsync: vulnerabilidades y CVE
Rsync tiene 22 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses17
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-70464 | Alta (8.7) | 0.57% | — | 13 ago 2026 | rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module… |
| CVE-2026-70462 | Alta (7.1) | 0.45% | — | 13 ago 2026 | rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying… |
| CVE-2026-70460 | Crítica (9.2) | 0.45% | — | 13 ago 2026 | rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir… |
| CVE-2026-70458 | Alta (8.8) | 0.40% | — | 13 ago 2026 | rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link… |
| CVE-2026-70456 | Alta (8.8) | 0.40% | — | 13 ago 2026 | rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument… |
| CVE-2026-70454 | Alta (7.6) | 0.19% | — | 13 ago 2026 | rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting… |
| CVE-2026-70453 | Alta (8.7) | 0.53% | — | 13 ago 2026 | rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can… |
| CVE-2026-70452 | Crítica (9.1) | 0.46% | — | 13 ago 2026 | rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation.… |
| CVE-2026-53796 | Media (5.8) | 0.11% | — | 13 ago 2026 | rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can manipulate destination path… |
| CVE-2026-53794 | Media (6.9) | 0.51% | — | 13 ago 2026 | rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers… |
| CVE-2026-53793 | Crítica (9.1) | 0.39% | — | 13 ago 2026 | rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the… |
| CVE-2026-53792 | Alta (7.1) | 0.45% | — | 13 ago 2026 | rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a… |
| CVE-2026-53790 | Crítica (9.2) | 0.63% | — | 13 ago 2026 | rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the… |
| CVE-2026-53788 | Media (6.9) | 0.34% | — | 13 ago 2026 | rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline… |
| CVE-2026-53785 | Media (6.9) | 0.17% | — | 13 ago 2026 | rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative… |
| CVE-2026-53783 | Alta (8.6) | 0.37% | — | 13 ago 2026 | rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by… |
| CVE-2025-10158 | Media (4.3) | 0.33% | — | 18 nov 2025 | A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the… |
| CVE-2024-12747 | Media (5.6) | 0.38% | — | 14 ene 2025 | A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a… |
| CVE-2007-6200 | Alta (10) | 4.9% | — | 1 dic 2007 | Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2)… |
| CVE-2007-6199 | Alta (9.3) | 4.1% | — | 1 dic 2007 | rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of… |
| CVE-2007-4091 | Media (6.8) | 3.3% | — | 16 ago 2007 | Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function. |
| CVE-2004-2093 | Media (4.6) | 1.00% | — | 9 feb 2004 | Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.