Skip to content

rsync: Peer-driven one-byte heap out-of-bounds write in add_implied_include()

High
tridge published GHSA-jhxm-j4mq-3fj4 Aug 13, 2026

Software

rsync

Affected versions

>= 3.2.5, <= 3.4.4

Patched versions

3.5.0

Description

add_implied_include() builds an implied "/**" filter rule from each transfer
argument the client sends, so the remote sender can validate the file list
against it. It under-counted a trailing backslash when sizing the buffer for
that rule, so the rule was written one byte past a heap allocation. The value
that overflows is supplied by the peer.

Demonstrated against a standard network rsync --daemon with a READ-ONLY
module: a remote, unauthenticated client sends -r --files-from=<file> with a
files-from entry carrying both an interior and a trailing backslash (a\b\),
and forward_filesfrom_data() feeds it to add_implied_include() on the daemon
side. The per-module parse_arguments() runs with am_server == 0, so
trust_sender_args stays 0 and the implied-include path is active.

A read-only module is enough; no write access and no crafted protocol are
needed. The write is one byte and its content is constrained, so code
execution is not claimed; heap corruption is, and the regression detects it as
an ASan heap-buffer-overflow.


Affected: 3.2.5 through 3.4.4 (add_implied_include() entered in 3.2.5)

Fixed in: 3.5.0 (part of the malicious-peer robustness work)

Reporter: Greg Kroah-Hartman (daemon-protocol fuzzing)

Test: exclude-implied-trailing-backslash

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

CVE ID

CVE-2026-70461

Weaknesses

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer. Learn more on MITRE.

Credits