CVE-2026-53792

ADVISORY - nist

Summary

rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side.

EPSS Score: 0.00311 (0.234)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Validation of Array Index

Out-of-bounds Write


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in