ALPINE-CVE-2026-70457

Source
https://security.alpinelinux.org/vuln/CVE-2026-70457
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-70457.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2026-70457
Upstream
Published
2026-08-13T15:19:59.490Z
Modified
2026-09-01T23:30:02.660791119Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
[none]
Details

rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parsesizearg() where the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. When snprintf truncates the formatted size string, the return value equals the number of characters that would have been written including the truncated portion, and this value may exceed the array length. The subsequent indexed write targets memory outside the intended array bounds, corrupting .bss memory.

References

Affected packages

Alpine:v3.21 / rsync

Package

Name
rsync
Purl
pkg:apk/alpine/rsync?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.3
Fixed
3.5.0-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-70457.json"

Alpine:v3.22 / rsync

Package

Name
rsync
Purl
pkg:apk/alpine/rsync?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.3
Fixed
3.5.0-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-70457.json"

Alpine:v3.23 / rsync

Package

Name
rsync
Purl
pkg:apk/alpine/rsync?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.3
Fixed
3.5.0-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-70457.json"

Alpine:v3.24 / rsync

Package

Name
rsync
Purl
pkg:apk/alpine/rsync?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.3
Fixed
3.5.0-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-70457.json"