High severity8.2NVD Advisory· Published Aug 13, 2026· Updated Sep 8, 2026
CVE-2026-70458
CVE-2026-70458
Description
rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords4 versionspkg:rpm/almalinux/rsyncpkg:rpm/almalinux/rsync-daemonpkg:rpm/opensuse/rsync&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/rsync-rrsync
< 3.2.7-1.el9_8+ 3 more
- (no CPE)range: < 3.2.7-1.el9_8
- (no CPE)range: < 3.2.7-1.el9_8
- (no CPE)range: < 3.4.1-160000.6.1
- (no CPE)range: < 3.2.7-1.el9_8
Patches
Vulnerability mechanics
References
3News mentions
1- Rsync: 25 Vulnerabilities Disclosed Together, Affecting Versions Before 3.5.0Vypr Intelligence · Aug 13, 2026