OESA-2026-1172

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-1172
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-1172.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-1172
Upstream
Published
2026-01-16T11:10:12Z
Modified
2026-08-18T01:19:27Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
rsync security update
Details

Rsync is an open source utility that provides fast incremental file transfer. It uses the "rsync algorithm" which provides a very fast method for bringing remote files into sync. It does this by sending just the differences in the files across the link, without requiring that both sets of files are present at one of the ends of the link beforehand.

Security Fix(es):

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The

malicious

rsync client requires at least read access to the remote rsync module in order to trigger the issue.(CVE-2025-10158)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:24.03-LTS-SP2 / rsync

Package

Name
rsync
Purl
pkg:rpm/openEuler/rsync&distro=openEuler-24.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.2.7-7.oe2403sp2

Ecosystem specific

{
    "aarch64": [
        "rsync-3.2.7-7.oe2403sp2.aarch64.rpm",
        "rsync-debuginfo-3.2.7-7.oe2403sp2.aarch64.rpm",
        "rsync-debugsource-3.2.7-7.oe2403sp2.aarch64.rpm",
        "rsync-help-3.2.7-7.oe2403sp2.aarch64.rpm"
    ],
    "src": [
        "rsync-3.2.7-7.oe2403sp2.src.rpm"
    ],
    "x86_64": [
        "rsync-3.2.7-7.oe2403sp2.x86_64.rpm",
        "rsync-debuginfo-3.2.7-7.oe2403sp2.x86_64.rpm",
        "rsync-debugsource-3.2.7-7.oe2403sp2.x86_64.rpm",
        "rsync-help-3.2.7-7.oe2403sp2.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1172.json"