CVE-2026-43618General(samba / rsync)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rsync

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
rsync

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-21: 1Technical Details · 2026-05-21: 105-21
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • たなか@calnarsa
    General

    Copy Fail や Dirty Frag は大騒ぎなのに、CVSS 8.1 の rsync (CVE-2026-43618)が全然話題にならないのおもしろいな(おもしろくない...

    Post summary

    The post comments on rsync CVE‑2026‑43618, rated CVSS 8.1, noting it lacks attention compared to other high‑profile flaws, but provides no details on exploitation or remediation.

    0000082
    121 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsambarsync---

Explore more