VendorsSambarsyncany version
Vulnerabilities

Samba Rsync any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

36CVEs
CVE-2017-16548
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.
Published 2017-11-06 · Modified
9.8EPSS 0.058
CVE-2017-17434
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.
Published 2017-12-06 · Modified
9.8EPSS 0.033
CVE-2017-15994
rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the code has been copied for use in various GitHub projects.
Published 2017-10-29 · Modified
9.8EPSS 0.010
CVE-2026-53791
rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header
Published 2026-08-13 · Analyzed
9.1EPSS 0.007
CVE-2026-70461
rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry
Published 2026-08-13 · Analyzed
8.8EPSS 0.008
CVE-2026-70455
rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion
Published 2026-08-13 · Analyzed
8.7EPSS 0.008
CVE-2026-70463
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
Published 2026-08-13 · Analyzed
8.6EPSS 0.005
CVE-2026-53803
rsync < 3.5.0 Symlink Following Arbitrary File Overwrite
Published 2026-08-13 · Analyzed
8.5EPSS 0.002
CVE-2026-53802
rsync < 3.5.0 Arbitrary File Read via Symlink Following
Published 2026-08-13 · Analyzed
8.4EPSS 0.002
CVE-2026-53784
rsync < 3.5.0 Path Traversal via Symlink Module Root
Published 2026-08-13 · Analyzed
8.4EPSS 0.002
CVE-2026-70457
rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()
Published 2026-08-13 · Analyzed
8.3EPSS 0.005
CVE-2026-53801
rsync < 3.5.0 Symlink Race Condition Directory Traversal
Published 2026-08-13 · Analyzed
8.2EPSS 0.003
CVE-2026-43618
Rsync < 3.4.3 Integer Overflow Information Disclosure
Published 2026-05-20 · Modified
8.1EPSS 0.008
CVE-2026-53795
rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest
Published 2026-08-13 · Analyzed
8.1EPSS 0.006
CVE-2026-53789
rsync < 3.5.0 Arbitrary File Deletion via Malicious File List
Published 2026-08-13 · Analyzed
8.1EPSS 0.005
CVE-2014-2855
The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.
Published 2014-04-23 · Modified
7.8EPSS 0.041
CVE-2026-41035
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
Published 2026-04-16 · Modified
7.8EPSS 0.005
CVE-2026-29518
Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write
Published 2026-05-20 · Modified
7.8EPSS 0.001
CVE-2024-12085
Rsync: info leak via uninitialized stack contents
Published 2025-01-14 · Modified
7.5EPSS 0.088
CVE-2018-5764
The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.
Published 2018-01-17 · Modified
7.5EPSS 0.064
CVE-2024-12088
Rsync: --safe-links option bypass leads to path traversal
Published 2025-01-14 · Modified
7.5EPSS 0.047
CVE-2024-12087
Rsync: path traversal vulnerability in rsync
Published 2025-01-14 · Modified
7.5EPSS 0.023
CVE-2022-29154
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).
Published 2022-08-02 · Modified
7.4EPSS 0.022
CVE-2020-14387
A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4.
Published 2021-05-27 · Modified
7.4EPSS 0.011
CVE-2026-43619
Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls
Published 2026-05-20 · Analyzed
7.2EPSS 0.001
CVE-2026-53799
rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application
Published 2026-08-13 · Analyzed
7.2EPSS 0.001
CVE-2026-70459
rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry
Published 2026-08-13 · Analyzed
6.9EPSS 0.007
CVE-2026-43620
Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()
Published 2026-05-20 · Analyzed
6.9EPSS 0.005
CVE-2026-53798
rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping
Published 2026-08-13 · Analyzed
6.9EPSS 0.004
CVE-2026-53786
rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive
Published 2026-08-13 · Analyzed
6.9EPSS 0.004
CVE-2024-12086
Rsync: rsync server leaks arbitrary client files
Published 2025-01-14 · Modified
6.8EPSS 0.018
CVE-2026-43617
Rsync < 3.4.3 Authorization Bypass via Hostname Resolution
Published 2026-05-20 · Analyzed
6.3EPSS 0.003
CVE-2026-53800
rsync < 3.5.0 Symlink Race Condition via --remove-source-files
Published 2026-08-13 · Analyzed
5.7EPSS 0.001
CVE-2026-53797
rsync < 3.5.0 Symlink Race Condition Information Disclosure
Published 2026-08-13 · Analyzed
5.7EPSS 0.001
CVE-2026-45232
Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy
Published 2026-05-20 · Analyzed
3.7EPSS 0.003
CVE-2002-0080
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
Published 2002-06-25 · Modified
2.1EPSS 0.005