Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95840.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-95840
Upstream
Published
2026-08-13T15:20:00Z
Modified
2026-09-05T05:27:51Z
Summary
CVE-2026-70462 affecting package rsync 3.4.3-1
Details

rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSGIOTIMEOUT messages carrying non-positive (zero or negative) values. Attackers can craft malicious MSGIOTIMEOUT messages that cause the timeout variable to wrap to a non-positive value, preventing the timeout check from firing and enabling idle or stalled connections to hold daemon slots indefinitely, leading to resource exhaustion.

References

Affected packages

Azure Linux:3 / rsync

Package

Name
rsync
Purl
pkg:rpm/azure-linux/rsync

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.4.3-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95840.json"