Giuseppe Paternicola[verified]@giuseppe_1337Patch
The tweet reports a high‑severity use‑after‑free flaw in rsync 3.0.1‑3.4.1 triggered by the -X flag and urges users to apply the vendor patch immediately.
Open Source Security mailing list@oss_securityDisclosure
The post discloses a zero‑day use‑after‑free flaw in rsync’s xattr handling, affecting all 3.x versions with -X, and notes an unofficial fix.
Ferramentas Linux@Cezar_H_LinuxGeneral
The tweet urges users not to wait for patches for CVE-2026-41035 and encourages building detection tools, providing no technical or exploit details.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The text briefly announces a use‑after‑free vulnerability in rsync (CVE-2026‑41035) but provides only minimal technical detail and no information on exploits, patches, or real‑world impact.
CVE@CVEnewDisclosure
A use‑after‑free vulnerability (CVE‑2026‑41035) has been disclosed for rsync versions 3.0.1 through 3.4.1, triggered by an untrusted length value in a qsort call.