Bug 2469054 (CVE-2026-43618)
| Summary: | CVE-2026-43618 rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, security-response-team, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in rsync. An authenticated daemon peer can exploit an integer overflow vulnerability in the compressed-token decoder. By carefully manipulating the compressed-token, a malicious sender can trigger an overflow, leading to remote memory disclosure. This allows an attacker to leak sensitive process memory contents, including environment variables, passwords, and memory pointers, which significantly weakens Address Space Layout Randomization (ASLR) and can facilitate further exploitation.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2510209, 2510210, 2510211 | ||
| Bug Blocks: | |||
| Deadline: | 2026-05-20 | ||
|
Description
OSIDB Bzimport
2026-05-11 13:47:58 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:26332 https://access.redhat.com/errata/RHSA-2026:26332 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:26410 https://access.redhat.com/errata/RHSA-2026:26410 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:26408 https://access.redhat.com/errata/RHSA-2026:26408 |