CVE-2026-43620Patch(samba / rsync)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch samba rsync systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address, resulting in a deterministic SIGSEGV crash of the rsync client.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rsync

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
rsync

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-27: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-27: 105-27
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • WindowsForum@windowsforum
    Patch

    🪟 Rsync DoS (CVE-2026-43620) hitting rsync <3.4.3 is the reminder: your “trusted” admin file-transfer path can still faceplant. Patch WSL/containers fast—crash now, investigate later. https://windowsforum.com/threads/cve-2026-43620-rsync-dos-patch-rsync-3-4-3-across-wsl-containers.420008/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #DenialOfService #WslPatching #RsyncVulnerability #Cve202643620 https://t.co/rRwHlGOstI

    Post summary

    The post highlights a DoS vulnerability (CVE-2026-43620) impacting rsync versions below 3.4.3 and stresses the need for immediate patches on WSL/containers.

    0000049
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsambarsync---

Explore more