CVE-2026-70459

Source
https://cve.org/CVERecord?id=CVE-2026-70459
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70459.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-70459
Aliases
  • GHSA-p4v4-qxw9-q72m
Downstream
Related
Published
2026-08-13T14:43:32Z
Modified
2026-09-04T18:25:57Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry
Details

rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-908"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70459.json"
}
References

Affected packages

Git / git.samba.org/rsync.git/

Affected ranges

Type
GIT
Repo
https://git.samba.org/rsync.git/
Events
Introduced
4cb6197b21d9860736c8e6d81b8eb8cac53beb5a
Fixed
471e17dc0d68233db84db11be82c9f62f4661214
Database specific
Show details
{
    "cpe": "cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.5.0"
        }
    ],
    "source": "CPE_RANGE"
}
Type
GIT
Repo
https://github.com/rsyncproject/rsync
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "last_affected": "3.4.4"
        },
        {
            "fixed": "3.5.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v3.*
v3.0.0
v3.0.1
v3.0.1pre1
v3.0.1pre2
v3.0.1pre3
v3.0.2
v3.0.3
v3.0.3pre1
v3.0.3pre2
v3.0.3pre3
v3.1.0
v3.1.0pre1
v3.1.1
v3.1.1pre1
v3.1.1pre2
v3.1.2
v3.1.2pre1
v3.1.3
v3.1.3pre1
v3.2.0
v3.2.0pre1
v3.2.0pre2
v3.2.0pre3
v3.2.1
v3.2.1pre1
v3.2.2
v3.2.2pre1
v3.2.2pre2
v3.2.2pre3
v3.2.3
v3.2.3pre1
v3.2.4
v3.2.4pre1
v3.2.4pre2
v3.2.4pre3
v3.2.4pre4
v3.2.5
v3.2.5pre1
v3.2.5pre2
v3.2.6
v3.2.7
v3.2.7pre1
v3.3.0
v3.3.0pre1
v3.4
v3.4.0
v3.4.1
v3.4.2
v3.4.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70459.json"