Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95759.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-95759
Upstream
Published
2026-08-13T15:19:59Z
Modified
2026-08-31T05:26:27Z
Summary
CVE-2026-70458 affecting package rsync 3.4.3-1
Details

rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINKBUMP processing on file entries with the FLAGHLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing FSUM field in the filestruct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data.

References

Affected packages

Azure Linux:3 / rsync

Package

Name
rsync
Purl
pkg:rpm/azure-linux/rsync

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.4.3-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95759.json"