VendorsSambarsyncall versions
Vulnerabilities

Samba Rsync

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

41CVEs
CVE-2024-12084
Rsync: heap buffer overflow in rsync due to improper checksum length handling
Published 2025-01-15 · Modified
9.8EPSS 0.721
CVE-2017-16548
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.
Published 2017-11-06 · Modified
9.8EPSS 0.058
CVE-2017-17434
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.
Published 2017-12-06 · Modified
9.8EPSS 0.033
CVE-2017-15994
rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the code has been copied for use in various GitHub projects.
Published 2017-10-29 · Modified
9.8EPSS 0.010
CVE-2026-53791
rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header
Published 2026-08-13 · Analyzed
9.1EPSS 0.007
CVE-2026-70461
rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry
Published 2026-08-13 · Analyzed
8.8EPSS 0.008
CVE-2026-70455
rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion
Published 2026-08-13 · Analyzed
8.7EPSS 0.008
CVE-2026-70463
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
Published 2026-08-13 · Analyzed
8.6EPSS 0.005
CVE-2026-53803
rsync < 3.5.0 Symlink Following Arbitrary File Overwrite
Published 2026-08-13 · Analyzed
8.5EPSS 0.002
CVE-2026-53784
rsync < 3.5.0 Path Traversal via Symlink Module Root
Published 2026-08-13 · Analyzed
8.4EPSS 0.002
CVE-2026-53802
rsync < 3.5.0 Arbitrary File Read via Symlink Following
Published 2026-08-13 · Analyzed
8.4EPSS 0.002
CVE-2026-70457
rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()
Published 2026-08-13 · Analyzed
8.3EPSS 0.005
CVE-2026-53801
rsync < 3.5.0 Symlink Race Condition Directory Traversal
Published 2026-08-13 · Analyzed
8.2EPSS 0.003
CVE-2026-43618
Rsync < 3.4.3 Integer Overflow Information Disclosure
Published 2026-05-20 · Modified
8.1EPSS 0.008
CVE-2026-53795
rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest
Published 2026-08-13 · Analyzed
8.1EPSS 0.006
CVE-2026-53789
rsync < 3.5.0 Arbitrary File Deletion via Malicious File List
Published 2026-08-13 · Analyzed
8.1EPSS 0.005
CVE-2014-2855
The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.
Published 2014-04-23 · Modified
7.8EPSS 0.041
CVE-2026-41035
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
Published 2026-04-16 · Modified
7.8EPSS 0.005
CVE-2026-29518
Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write
Published 2026-05-20 · Modified
7.8EPSS 0.001
CVE-2024-12085
Rsync: info leak via uninitialized stack contents
Published 2025-01-14 · Modified
7.5EPSS 0.088
CVE-2018-5764
The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.
Published 2018-01-17 · Modified
7.5EPSS 0.064
CVE-2008-1720
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
Published 2008-04-10 · Modified
7.5EPSS 0.050
CVE-2024-12088
Rsync: --safe-links option bypass leads to path traversal
Published 2025-01-14 · Modified
7.5EPSS 0.047
CVE-2024-12087
Rsync: path traversal vulnerability in rsync
Published 2025-01-14 · Modified
7.5EPSS 0.023
CVE-2022-29154
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).
Published 2022-08-02 · Modified
7.4EPSS 0.022
CVE-2020-14387
A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4.
Published 2021-05-27 · Modified
7.4EPSS 0.011
CVE-2026-43619
Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls
Published 2026-05-20 · Analyzed
7.2EPSS 0.001
CVE-2026-53799
rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application
Published 2026-08-13 · Analyzed
7.2EPSS 0.001
CVE-2026-70459
rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry
Published 2026-08-13 · Analyzed
6.9EPSS 0.007
CVE-2026-43620
Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()
Published 2026-05-20 · Analyzed
6.9EPSS 0.005
CVE-2026-53798
rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping
Published 2026-08-13 · Analyzed
6.9EPSS 0.004
CVE-2026-53786
rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive
Published 2026-08-13 · Analyzed
6.9EPSS 0.004
CVE-2024-12086
Rsync: rsync server leaks arbitrary client files
Published 2025-01-14 · Modified
6.8EPSS 0.018
CVE-2014-9512
rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.
Published 2015-02-12 · Modified
6.4EPSS 0.065
CVE-2026-43617
Rsync < 3.4.3 Authorization Bypass via Hostname Resolution
Published 2026-05-20 · Analyzed
6.3EPSS 0.003
CVE-2026-53797
rsync < 3.5.0 Symlink Race Condition Information Disclosure
Published 2026-08-13 · Analyzed
5.7EPSS 0.001
CVE-2026-53800
rsync < 3.5.0 Symlink Race Condition via --remove-source-files
Published 2026-08-13 · Analyzed
5.7EPSS 0.001
CVE-2011-1097
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
Published 2011-03-30 · Modified
5.1EPSS 0.032
CVE-2017-17433
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended access restrictions.
Published 2017-12-06 · Modified
4.3EPSS 0.018
CVE-2026-45232
Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy
Published 2026-05-20 · Analyzed
3.7EPSS 0.003
1 / 2Next →