Rsync是RsyncProject开源的一款快速且用途广泛的文件复制工具。用于远程文件和本地文件。 Rsync 3.4.2及之前版本存在后置链接漏洞,该漏洞源于路径系统调用中存在符号链接竞争条件,本地攻击者可通过交换符号链接将操作重定向到导出模块外的文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| RsyncProject | rsync | < 3.4.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RsyncProject | rsync | 0 ~ 3.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43618 | 8.1 HIGH | Rsync < 3.4.3 Integer Overflow Information Disclosure |
| CVE-2026-29518 | 7.0 HIGH | Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write |
| CVE-2026-43620 | 6.5 MEDIUM | Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files() |
| CVE-2026-43617 | 4.8 MEDIUM | Rsync < 3.4.3 Authorization Bypass via Hostname Resolution |
| CVE-2026-45232 | 3.1 LOW | Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy |
No comments yet